Files
ARC/backend/app/sandbox/rules/owasp-top-ten.yaml

41422 lines
1.4 MiB

rules:
- id: generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host
paths:
include:
- '*.conf'
- '*.vhost'
- '**/sites-available/*'
- '**/sites-enabled/*'
languages:
- generic
severity: WARNING
message: The host for this proxy URL is dynamically determined. This can be dangerous
if the host can be injected by an attacker because it may forcibly alter destination
of the proxy. Consider hardcoding acceptable destinations and retrieving them
with 'map' or something similar.
metadata:
source-rule-url: https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md
references:
- https://nginx.org/en/docs/http/ngx_http_map_module.html
category: security
technology:
- nginx
confidence: MEDIUM
cwe:
- 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host
shortlink: https://sg.run/ndpb
semgrep.dev:
rule:
r_id: 9036
rv_id: 1262671
rule_id: GdU7yl
version_id: kbTzG2j
url: https://semgrep.dev/playground/r/kbTzG2j/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host
origin: community
pattern-either:
- pattern: proxy_pass $SCHEME://$$HOST ...;
- pattern: proxy_pass $$SCHEME://$$HOST ...;
- id: generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme
paths:
include:
- '*.conf'
- '*.vhost'
- '**/sites-available/*'
- '**/sites-enabled/*'
languages:
- generic
severity: WARNING
message: The protocol scheme for this proxy is dynamically determined. This can
be dangerous if the scheme can be injected by an attacker because it may forcibly
alter the connection scheme. Consider hardcoding a scheme for this proxy.
metadata:
cwe:
- 'CWE-16: CWE CATEGORY: Configuration'
references:
- https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md
category: security
technology:
- nginx
confidence: MEDIUM
owasp:
- A06:2017 - Security Misconfiguration
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme
shortlink: https://sg.run/EkAo
semgrep.dev:
rule:
r_id: 9037
rv_id: 1262672
rule_id: ReUg7n
version_id: w8TRoAJ
url: https://semgrep.dev/playground/r/w8TRoAJ/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme
origin: community
pattern: proxy_pass $$SCHEME:// ...;
- id: generic.nginx.security.header-injection.header-injection
pattern: |
location ... <$VARIABLE> ... {
...
add_header ... $$VARIABLE
...
}
paths:
include:
- '*.conf'
- '*.vhost'
- '**/sites-available/*'
- '**/sites-enabled/*'
languages:
- generic
severity: ERROR
message: 'The $$VARIABLE path parameter is added as a header in the response. This
could allow an attacker to inject a newline and add a new header into the response.
This is called HTTP response splitting. To fix, do not allow whitespace in the
path parameter: ''[^\s]+''.'
metadata:
cwe:
- 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP
Request/Response Splitting'')'
references:
- https://github.com/yandex/gixy/blob/master/docs/en/plugins/httpsplitting.md
- https://owasp.org/www-community/attacks/HTTP_Response_Splitting
category: security
technology:
- nginx
confidence: MEDIUM
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/generic.nginx.security.header-injection.header-injection
shortlink: https://sg.run/7oj4
semgrep.dev:
rule:
r_id: 9038
rv_id: 1262673
rule_id: AbUz8p
version_id: xyTjzNW
url: https://semgrep.dev/playground/r/xyTjzNW/generic.nginx.security.header-injection.header-injection
origin: community
- id: generic.nginx.security.insecure-ssl-version.insecure-ssl-version
patterns:
- pattern-not: ssl_protocols TLSv1.2 TLSv1.3;
- pattern-not: ssl_protocols TLSv1.3 TLSv1.2;
- pattern-not: ssl_protocols TLSv1.2;
- pattern-not: ssl_protocols TLSv1.3;
- pattern: ssl_protocols ...;
paths:
include:
- '*.conf'
- '*.vhost'
- '**/sites-available/*'
- '**/sites-enabled/*'
languages:
- generic
severity: WARNING
message: Detected use of an insecure SSL version. Secure SSL versions are TLSv1.2
and TLS1.3; older versions are known to be broken and are susceptible to attacks.
Prefer use of TLSv1.2 or later.
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
references:
- https://www.acunetix.com/blog/web-security-zone/hardening-nginx/
- https://www.acunetix.com/blog/articles/tls-ssl-cipher-hardening/
category: security
technology:
- nginx
confidence: HIGH
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/generic.nginx.security.insecure-ssl-version.insecure-ssl-version
shortlink: https://sg.run/gLKy
semgrep.dev:
rule:
r_id: 9041
rv_id: 1262676
rule_id: WAUo9k
version_id: vdT06O4
url: https://semgrep.dev/playground/r/vdT06O4/generic.nginx.security.insecure-ssl-version.insecure-ssl-version
origin: community
- id: generic.nginx.security.missing-ssl-version.missing-ssl-version
patterns:
- pattern: server { ... listen $PORT ssl; ... }
- pattern-not-inside: server { ... ssl_protocols ... }
paths:
include:
- '*.conf'
- '*.vhost'
- '**/sites-available/*'
- '**/sites-enabled/*'
languages:
- generic
severity: WARNING
message: This server configuration is missing the 'ssl_protocols' directive. By
default, this server will use 'ssl_protocols TLSv1 TLSv1.1 TLSv1.2', and versions
older than TLSv1.2 are known to be broken. Explicitly specify 'ssl_protocols TLSv1.2
TLSv1.3' to use secure TLS versions.
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
references:
- https://www.acunetix.com/blog/web-security-zone/hardening-nginx/
- https://nginx.org/en/docs/http/configuring_https_servers.html
category: security
technology:
- nginx
confidence: MEDIUM
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/generic.nginx.security.missing-ssl-version.missing-ssl-version
shortlink: https://sg.run/3xzl
semgrep.dev:
rule:
r_id: 9043
rv_id: 1262678
rule_id: KxUbeA
version_id: ZRTKAle
url: https://semgrep.dev/playground/r/ZRTKAle/generic.nginx.security.missing-ssl-version.missing-ssl-version
origin: community
- id: generic.nginx.security.request-host-used.request-host-used
pattern-either:
- pattern: $http_host
- pattern: $host
paths:
include:
- '*conf*'
- '*nginx*'
- '*vhost*'
- '**/sites-available/*'
- '**/sites-enabled/*'
languages:
- generic
severity: WARNING
message: '''$http_host'' and ''$host'' variables may contain a malicious value from
attacker controlled ''Host'' request header. Use an explicitly configured host
value or a allow list for validation.'
metadata:
cwe:
- 'CWE-290: Authentication Bypass by Spoofing'
references:
- https://github.com/yandex/gixy/blob/master/docs/en/plugins/hostspoofing.md
- https://portswigger.net/web-security/host-header
category: security
technology:
- nginx
confidence: MEDIUM
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/generic.nginx.security.request-host-used.request-host-used
shortlink: https://sg.run/4x3Z
semgrep.dev:
rule:
r_id: 9044
rv_id: 1262680
rule_id: qNUjGg
version_id: ExTExrN
url: https://semgrep.dev/playground/r/ExTExrN/generic.nginx.security.request-host-used.request-host-used
origin: community
- id: generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key
pattern-regex: rk_live_[0-9a-zA-Z]{24}
languages:
- regex
message: Stripe Restricted API Key detected
severity: ERROR
metadata:
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json
category: security
technology:
- secrets
- stripe
confidence: MEDIUM
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
references:
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key
shortlink: https://sg.run/ZvdL
semgrep.dev:
rule:
r_id: 9079
rv_id: 1262900
rule_id: 5rUOWq
version_id: K3TKkKj
url: https://semgrep.dev/playground/r/K3TKkKj/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key
origin: community
- id: generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri
patterns:
- pattern: $PROTOCOL://$...USERNAME:$...PASSWORD@$END
- metavariable-regex:
metavariable: $...USERNAME
regex: \A({?)([A-Za-z])([A-Za-z0-9_-]){5,31}(}?)\Z
- metavariable-regex:
metavariable: $...PASSWORD
regex: (?!.*[\s])(?=.*[0-9])(?=.*[a-z])(?=.*[A-Z])(?=.*[!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~]){6,32}
- metavariable-regex:
metavariable: $PROTOCOL
regex: (.*http.*)|(.*sql.*)|(.*ftp.*)|(.*smtp.*)
languages:
- generic
message: Username and password in URI detected
severity: ERROR
metadata:
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
references:
- https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go
category: security
technology:
- secrets
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri
shortlink: https://sg.run/8yA4
semgrep.dev:
rule:
r_id: 9084
rv_id: 1262903
rule_id: DbUple
version_id: YDTZeZE
url: https://semgrep.dev/playground/r/YDTZeZE/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri
origin: community
- id: go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly
patterns:
- pattern-not-inside: |
&sessions.Options{
...,
HttpOnly: true,
...,
}
- pattern: |
&sessions.Options{
...,
}
message: A session cookie was detected without setting the 'HttpOnly' flag. The
'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts
from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by
setting 'HttpOnly' to 'true' in the Options struct.
metadata:
cwe:
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69
category: security
technology:
- gorilla
confidence: MEDIUM
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly
shortlink: https://sg.run/4xJZ
semgrep.dev:
rule:
r_id: 9088
rv_id: 1262911
rule_id: qNUj6g
version_id: WrTqKqe
url: https://semgrep.dev/playground/r/WrTqKqe/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly
origin: community
fix-regex:
regex: (HttpOnly\s*:\s+)false
replacement: \1true
severity: WARNING
languages:
- go
- id: go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure
patterns:
- pattern-not-inside: |
&sessions.Options{
...,
Secure: true,
...,
}
- pattern: |
&sessions.Options{
...,
}
message: A session cookie was detected without setting the 'Secure' flag. The 'secure'
flag for cookies prevents the client from transmitting the cookie over insecure
channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in
the Options struct.
metadata:
cwe:
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69
category: security
technology:
- gorilla
confidence: MEDIUM
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure
shortlink: https://sg.run/PJdE
semgrep.dev:
rule:
r_id: 9089
rv_id: 1262912
rule_id: lBU9kw
version_id: 0bTKzKk
url: https://semgrep.dev/playground/r/0bTKzKk/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure
origin: community
fix-regex:
regex: (Secure\s*:\s+)false
replacement: \1true
severity: WARNING
languages:
- go
- id: go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection
metadata:
cwe:
- 'CWE-300: Channel Accessible by Non-Endpoint'
references:
- https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption
category: security
technology:
- grpc
confidence: HIGH
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection
shortlink: https://sg.run/J9yZ
semgrep.dev:
rule:
r_id: 9090
rv_id: 1262916
rule_id: PeUZ4X
version_id: YDTZeZB
url: https://semgrep.dev/playground/r/YDTZeZB/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection
origin: community
message: 'Found an insecure gRPC connection using ''grpc.WithInsecure()''. This
creates a connection without encryption to a gRPC server. A malicious attacker
could tamper with the gRPC message, which could compromise the machine. Instead,
establish a secure connection with an SSL certificate using the ''grpc.WithTransportCredentials()''
function. You can create a create credentials using a ''tls.Config{}'' struct
with ''credentials.NewTLS()''. The final fix looks like this: ''grpc.WithTransportCredentials(credentials.NewTLS(<config>))''.'
languages:
- go
severity: ERROR
pattern: $GRPC.Dial($ADDR, ..., $GRPC.WithInsecure(...), ...)
fix-regex:
regex: (.*)WithInsecure\(.*?\)
replacement: \1WithTransportCredentials(credentials.NewTLS(<your_tls_config_here>))
- id: go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection
metadata:
cwe:
- 'CWE-300: Channel Accessible by Non-Endpoint'
references:
- https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption
category: security
technology:
- grpc
confidence: HIGH
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection
shortlink: https://sg.run/5Q5l
semgrep.dev:
rule:
r_id: 9091
rv_id: 1262917
rule_id: JDUy0B
version_id: 6xT2923
url: https://semgrep.dev/playground/r/6xT2923/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection
origin: community
message: Found an insecure gRPC server without 'grpc.Creds()' or options with credentials.
This allows for a connection without encryption to this server. A malicious attacker
could tamper with the gRPC message, which could compromise the machine. Include
credentials derived from an SSL certificate in order to create a secure gRPC connection.
You can create credentials using 'credentials.NewServerTLSFromFile("cert.pem",
"cert.key")'.
languages:
- go
severity: ERROR
mode: taint
pattern-sinks:
- requires: OPTIONS and not CREDS
pattern: grpc.NewServer($OPT, ...)
- requires: EMPTY_CONSTRUCTOR
pattern: grpc.NewServer()
pattern-sources:
- label: OPTIONS
pattern: grpc.ServerOption{ ... }
- label: CREDS
pattern: grpc.Creds(...)
- label: EMPTY_CONSTRUCTOR
pattern: grpc.NewServer()
- id: go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
assumes the integrity of the token has already been verified. This would allow
a malicious actor to forge a JWT token that will automatically be verified. Do
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
category: security
technology:
- jwt
confidence: HIGH
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm
shortlink: https://sg.run/Gej1
semgrep.dev:
rule:
r_id: 9092
rv_id: 1262919
rule_id: 5rUOWQ
version_id: zyTb2bz
url: https://semgrep.dev/playground/r/zyTb2bz/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm
origin: community
languages:
- go
severity: ERROR
patterns:
- pattern-either:
- pattern-inside: |
import "github.com/golang-jwt/jwt"
...
- pattern-inside: |
import "github.com/dgrijalva/jwt-go"
...
- pattern-either:
- pattern: |
jwt.SigningMethodNone
- pattern: jwt.UnsafeAllowNoneSignatureType
- id: go.jwt-go.security.jwt.hardcoded-jwt-key
message: A hard-coded credential was detected. It is not recommended to store credentials
in source-code, as this risks secrets being leaked and used by either an internal
or external malicious adversary. It is recommended to use environment variables
to securely provide credentials or retrieve credentials from a secure vault or
HSM (Hardware Security Module).
options:
interfile: true
metadata:
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
category: security
technology:
- jwt
- secrets
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/go.jwt-go.security.jwt.hardcoded-jwt-key
shortlink: https://sg.run/Rod2
semgrep.dev:
rule:
r_id: 9093
rv_id: 1262920
rule_id: GdU7Ny
version_id: pZT0305
url: https://semgrep.dev/playground/r/pZT0305/go.jwt-go.security.jwt.hardcoded-jwt-key
origin: community
severity: WARNING
languages:
- go
mode: taint
pattern-sources:
- patterns:
- pattern-inside: |
[]byte("$F")
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
$TOKEN.SignedString($F)
- focus-metavariable: $F
- id: go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified
message: Detected the decoding of a JWT token without a verify step. Don't use `ParseUnverified`
unless you know what you're doing This method parses the token but doesn't validate
the signature. It's only ever useful in cases where you know the signature is
valid (because it has been checked previously in the stack) and you want to extract
values from it.
metadata:
cwe:
- 'CWE-345: Insufficient Verification of Data Authenticity'
owasp:
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
category: security
technology:
- jwt
confidence: MEDIUM
references:
- https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified
shortlink: https://sg.run/Av66
semgrep.dev:
rule:
r_id: 9094
rv_id: 1262918
rule_id: ReUgJJ
version_id: o5TbDbq
url: https://semgrep.dev/playground/r/o5TbDbq/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified
origin: community
languages:
- go
severity: WARNING
patterns:
- pattern-inside: |
import "github.com/dgrijalva/jwt-go"
...
- pattern: |
$JWT.ParseUnverified(...)
- id: go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd
patterns:
- pattern-either:
- patterns:
- pattern: |
exec.Cmd {...,Path: $CMD,...}
- pattern-not: |
exec.Cmd {...,Path: "...",...}
- pattern-not-inside: |
$CMD,$ERR := exec.LookPath("...");
...
- pattern-not-inside: |
$CMD = "...";
...
- patterns:
- pattern: |
exec.Cmd {...,Args: $ARGS,...}
- pattern-not: |
exec.Cmd {...,Args: []string{...},...}
- pattern-not-inside: |
$ARGS = []string{"...",...};
...
- pattern-not-inside: |
$CMD = "...";
...
$ARGS = []string{$CMD,...};
...
- pattern-not-inside: |
$CMD = exec.LookPath("...");
...
$ARGS = []string{$CMD,...};
...
- patterns:
- pattern: |
exec.Cmd {...,Args: []string{$CMD,...},...}
- pattern-not: |
exec.Cmd {...,Args: []string{"...",...},...}
- pattern-not-inside: |
$CMD,$ERR := exec.LookPath("...");
...
- pattern-not-inside: |
$CMD = "...";
...
- patterns:
- pattern-either:
- pattern: |
exec.Cmd {...,Args: []string{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$EXE,...},...}
- patterns:
- pattern: |
exec.Cmd {...,Args: []string{$CMD,"-c",$EXE,...},...}
- pattern-inside: |
$CMD,$ERR := exec.LookPath("=~/(sh|bash|ksh|csh|tcsh|zsh)/");
...
- pattern-not: |
exec.Cmd {...,Args: []string{"...","...","...",...},...}
- pattern-not-inside: |
$EXE = "...";
...
- pattern-inside: |
import "os/exec"
...
message: Detected non-static command inside exec.Cmd. Audit the input to 'exec.Cmd'.
If unverified user data can reach this call site, this is a code injection vulnerability.
A malicious actor can inject a malicious script to execute arbitrary code.
metadata:
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- go
confidence: MEDIUM
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
subcategory:
- audit
likelihood: LOW
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd
shortlink: https://sg.run/Dorj
semgrep.dev:
rule:
r_id: 9108
rv_id: 1262934
rule_id: 2ZUb8l
version_id: e1Tyjeg
url: https://semgrep.dev/playground/r/e1Tyjeg/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd
origin: community
severity: ERROR
languages:
- go
- id: go.lang.security.audit.crypto.bad_imports.insecure-module-used
message: The package `net/http/cgi` is on the import blocklist. The package is
vulnerable to httpoxy attacks (CVE-2015-5386). It is recommended to use `net/http`
or a web framework to build a web application instead.
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
source-rule-url: https://github.com/securego/gosec
references:
- https://godoc.org/golang.org/x/crypto/sha3
category: security
technology:
- go
confidence: MEDIUM
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/go.lang.security.audit.crypto.bad_imports.insecure-module-used
shortlink: https://sg.run/l2gj
semgrep.dev:
rule:
r_id: 9113
rv_id: 1262921
rule_id: yyUnov
version_id: 2KTv2vJ
url: https://semgrep.dev/playground/r/2KTv2vJ/go.lang.security.audit.crypto.bad_imports.insecure-module-used
origin: community
languages:
- go
severity: WARNING
pattern-either:
- patterns:
- pattern-inside: |
import "net/http/cgi"
...
- pattern: |
cgi.$FUNC(...)
- id: go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key
message: Disabled host key verification detected. This allows man-in-the-middle
attacks. Use the 'golang.org/x/crypto/ssh/knownhosts' package to do host key verification.
See https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ to
learn more about the problem and how to fix it.
metadata:
cwe:
- 'CWE-322: Key Exchange without Entity Authentication'
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/securego/gosec
references:
- https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/
- https://gist.github.com/Skarlso/34321a230cf0245018288686c9e70b2d
category: security
technology:
- go
confidence: MEDIUM
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key
shortlink: https://sg.run/Yv6X
semgrep.dev:
rule:
r_id: 9114
rv_id: 1262922
rule_id: r6UrW9
version_id: X0TzyzN
url: https://semgrep.dev/playground/r/X0TzyzN/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key
origin: community
languages:
- go
severity: WARNING
pattern: ssh.InsecureIgnoreHostKey()
- id: go.lang.security.audit.crypto.math_random.math-random-used
metadata:
cwe:
- 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)'
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#secure-random-number-generation
category: security
technology:
- go
confidence: MEDIUM
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/go.lang.security.audit.crypto.math_random.math-random-used
shortlink: https://sg.run/6nK6
semgrep.dev:
rule:
r_id: 9115
rv_id: 1262923
rule_id: bwUwy8
version_id: jQTn5nj
url: https://semgrep.dev/playground/r/jQTn5nj/go.lang.security.audit.crypto.math_random.math-random-used
origin: community
message: Do not use `math/rand`. Use `crypto/rand` instead.
languages:
- go
severity: WARNING
patterns:
- pattern-either:
- pattern: |
import $RAND "$MATH"
- pattern: |
import "$MATH"
- metavariable-regex:
metavariable: $MATH
regex: ^(math/rand(\/v[0-9]+)*)$
- pattern-either:
- pattern-inside: |
...
rand.$FUNC(...)
- pattern-inside: |
...
$RAND.$FUNC(...)
- focus-metavariable:
- $MATH
fix: |
crypto/rand
- id: go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion
message: '`MinVersion` is missing from this TLS configuration. By default, as of
Go 1.22, TLS 1.2 is currently used as the minimum. General purpose web applications
should default to TLS 1.3 with all other protocols disabled. Only where it is
known that a web server must support legacy clients with unsupported an insecure
browsers (such as Internet Explorer 10), it may be necessary to enable TLS 1.0
to provide support. Add `MinVersion: tls.VersionTLS13'' to the TLS configuration
to bump the minimum version to TLS 1.3.'
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go
references:
- https://go.dev/doc/go1.22#minor_library_changes
- https://pkg.go.dev/crypto/tls#:~:text=MinVersion
- https://www.us-cert.gov/ncas/alerts/TA14-290A
category: security
technology:
- go
confidence: HIGH
subcategory:
- audit
likelihood: MEDIUM
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion
shortlink: https://sg.run/oxEN
semgrep.dev:
rule:
r_id: 9116
rv_id: 1262924
rule_id: NbUk4X
version_id: 1QTypyp
url: https://semgrep.dev/playground/r/1QTypyp/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion
origin: community
languages:
- go
severity: WARNING
patterns:
- pattern: |
tls.Config{ $...CONF }
- pattern-not: |
tls.Config{..., MinVersion: ..., ...}
fix: |
tls.Config{ $...CONF, MinVersion: tls.VersionTLS13 }
- id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure
message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14,
SSLv3 will be removed. Instead, use 'tls.VersionTLS13'.
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go
references:
- https://golang.org/doc/go1.14#crypto/tls
- https://www.us-cert.gov/ncas/alerts/TA14-290A
category: security
technology:
- go
confidence: HIGH
subcategory:
- vuln
likelihood: MEDIUM
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure
shortlink: https://sg.run/zvE1
semgrep.dev:
rule:
r_id: 9117
rv_id: 1262926
rule_id: kxUkJ2
version_id: yeTxpxj
url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure
origin: community
languages:
- go
severity: WARNING
fix-regex:
regex: VersionSSL30
replacement: VersionTLS13
pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}'
- id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher
message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered
weak. Use the function 'tls.CipherSuites()' to get a list of good cipher suites.
See https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other
cipher suites to use.
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go
references:
- https://golang.org/pkg/crypto/tls/#InsecureCipherSuites
category: security
technology:
- go
confidence: HIGH
subcategory:
- vuln
likelihood: HIGH
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher
shortlink: https://sg.run/px8N
semgrep.dev:
rule:
r_id: 9118
rv_id: 1262927
rule_id: wdUJYk
version_id: rxTAKAZ
url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher
origin: community
languages:
- go
severity: WARNING
pattern-either:
- pattern: |
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}}
- pattern: |
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}}
- pattern: |
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}}
- pattern: |
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}}
- pattern: |
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}}
- pattern: |
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}}
- pattern: |
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}}
- pattern: |
tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}}
- pattern: |
tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...}
- pattern: |
tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}
- pattern: |
tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...}
- pattern: |
tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}
- pattern: |
tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}
- pattern: |
tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}
- pattern: |
tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}
- pattern: |
tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}
- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
resistant and is therefore not suitable as a cryptographic signature. Use SHA256
or SHA3 instead.
languages:
- go
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-328: Use of Weak Hash'
source-rule-url: https://github.com/securego/gosec#available-rules
category: security
technology:
- go
confidence: MEDIUM
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5
shortlink: https://sg.run/2xB5
semgrep.dev:
rule:
r_id: 9119
rv_id: 1262928
rule_id: x8Un6q
version_id: bZT535Y
url: https://semgrep.dev/playground/r/bZT535Y/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5
origin: community
patterns:
- pattern-inside: |
import "crypto/md5"
...
- pattern-either:
- pattern: |
md5.New()
- pattern: |
md5.Sum(...)
- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
collision resistant and is therefore not suitable as a cryptographic signature.
Use SHA256 or SHA3 instead.
languages:
- go
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-328: Use of Weak Hash'
source-rule-url: https://github.com/securego/gosec#available-rules
category: security
technology:
- go
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1
shortlink: https://sg.run/XBYA
semgrep.dev:
rule:
r_id: 9120
rv_id: 1262929
rule_id: OrU31O
version_id: NdTzyz1
url: https://semgrep.dev/playground/r/NdTzyz1/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1
origin: community
patterns:
- pattern-inside: |
import "crypto/sha1"
...
- pattern-either:
- pattern: |
sha1.New()
- pattern: |
sha1.Sum(...)
- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES
message: Detected DES cipher algorithm which is insecure. The algorithm is considered
weak and has been deprecated. Use AES instead.
languages:
- go
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
source-rule-url: https://github.com/securego/gosec#available-rules
category: security
technology:
- go
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES
shortlink: https://sg.run/jREA
semgrep.dev:
rule:
r_id: 9121
rv_id: 1262930
rule_id: eqU8B3
version_id: kbTzGzA
url: https://semgrep.dev/playground/r/kbTzGzA/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES
origin: community
patterns:
- pattern-inside: |
import "crypto/des"
...
- pattern-either:
- pattern: |
des.NewTripleDESCipher(...)
- pattern: |
des.NewCipher(...)
- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4
message: Detected RC4 cipher algorithm which is insecure. The algorithm has many
known vulnerabilities. Use AES instead.
languages:
- go
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
source-rule-url: https://github.com/securego/gosec#available-rules
category: security
technology:
- go
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4
shortlink: https://sg.run/1ZAD
semgrep.dev:
rule:
r_id: 9122
rv_id: 1262931
rule_id: v8Unl0
version_id: w8TRoRQ
url: https://semgrep.dev/playground/r/w8TRoRQ/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4
origin: community
patterns:
- pattern-inside: |
import "crypto/rc4"
...
- pattern: rc4.NewCipher(...)
- id: go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key
message: RSA keys should be at least 2048 bits
languages:
- go
severity: WARNING
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/securego/gosec/blob/master/rules/rsa.go
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
category: security
technology:
- go
confidence: HIGH
subcategory:
- audit
likelihood: HIGH
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key
shortlink: https://sg.run/9oY4
semgrep.dev:
rule:
r_id: 9123
rv_id: 1262932
rule_id: d8UjY3
version_id: xyTjz8L
url: https://semgrep.dev/playground/r/xyTjz8L/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key
origin: community
patterns:
- pattern-either:
- pattern: |
rsa.GenerateKey(..., $BITS)
- pattern: |
rsa.GenerateMultiPrimeKey(..., $BITS)
- metavariable-comparison:
metavariable: $BITS
comparison: $BITS < 2048
- focus-metavariable:
- $BITS
fix: |
2048
- id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces
message: Detected a network listener listening on 0.0.0.0 or an empty string. This
could unexpectedly expose the server publicly as it binds to all available interfaces.
Instead, specify another IP address that is not 0.0.0.0 nor the empty string.
languages:
- go
severity: WARNING
metadata:
cwe:
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
source-rule-url: https://github.com/securego/gosec
category: security
technology:
- go
confidence: HIGH
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces
shortlink: https://sg.run/rdE0
semgrep.dev:
rule:
r_id: 9125
rv_id: 1262939
rule_id: nJUz3J
version_id: ExTExoK
url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces
origin: community
pattern-either:
- pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...)
- pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...)
- pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...)
- pattern: net.Listen($NETWORK, "=~/^:.*$/", ...)
- id: go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly
patterns:
- pattern-not-inside: |
http.Cookie{
...,
HttpOnly: true,
...,
}
- pattern: |
http.Cookie{
...,
}
message: A session cookie was detected without setting the 'HttpOnly' flag. The
'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts
from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by
setting 'HttpOnly' to 'true' in the Cookie.
metadata:
cwe:
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go
- https://golang.org/src/net/http/cookie.go
category: security
technology:
- go
confidence: MEDIUM
subcategory:
- vuln
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly
shortlink: https://sg.run/b73e
semgrep.dev:
rule:
r_id: 9126
rv_id: 1262940
rule_id: EwU2Z6
version_id: 7ZTE3BW
url: https://semgrep.dev/playground/r/7ZTE3BW/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly
origin: community
fix-regex:
regex: (HttpOnly\s*:\s+)false
replacement: \1true
severity: WARNING
languages:
- go
- id: go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure
patterns:
- pattern-not-inside: |
http.Cookie{
...,
Secure: true,
...,
}
- pattern: |
http.Cookie{
...,
}
message: A session cookie was detected without setting the 'Secure' flag. The 'secure'
flag for cookies prevents the client from transmitting the cookie over insecure
channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in
the Options struct.
metadata:
cwe:
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go
- https://golang.org/src/net/http/cookie.go
category: security
technology:
- go
confidence: MEDIUM
subcategory:
- vuln
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure
shortlink: https://sg.run/N4G7
semgrep.dev:
rule:
r_id: 9127
rv_id: 1262941
rule_id: 7KUQ8X
version_id: LjTkgGE
url: https://semgrep.dev/playground/r/LjTkgGE/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure
origin: community
fix-regex:
regex: (Secure\s*:\s+)false
replacement: \1true
severity: WARNING
languages:
- go
- id: go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace
message: Detected a potentially dynamic ClientTrace. This occurred because semgrep
could not find a static definition for '$TRACE'. Dynamic ClientTraces are dangerous
because they deserialize function code to run when certain Request events occur,
which could lead to code being run without your knowledge. Ensure that your ClientTrace
is statically defined.
metadata:
cwe:
- 'CWE-913: Improper Control of Dynamically-Managed Code Resources'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://github.com/returntocorp/semgrep-rules/issues/518
category: security
technology:
- go
confidence: MEDIUM
subcategory:
- vuln
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace
shortlink: https://sg.run/kXEK
semgrep.dev:
rule:
r_id: 9128
rv_id: 1262942
rule_id: L1Uyjp
version_id: 8KT5rNv
url: https://semgrep.dev/playground/r/8KT5rNv/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace
origin: community
patterns:
- pattern-not-inside: |
package $PACKAGE
...
&httptrace.ClientTrace { ... }
...
- pattern: httptrace.WithClientTrace($ANY, $TRACE)
severity: WARNING
languages:
- go
- id: go.lang.security.audit.net.formatted-template-string.formatted-template-string
message: Found a formatted template string passed to 'template.HTML()'. 'template.HTML()'
does not escape contents. Be absolutely sure there is no user-controlled data
in this template. If user data can reach this template, you may have a XSS vulnerability.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://golang.org/pkg/html/template/#HTML
category: security
technology:
- go
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/go.lang.security.audit.net.formatted-template-string.formatted-template-string
shortlink: https://sg.run/weE0
semgrep.dev:
rule:
r_id: 9129
rv_id: 1262943
rule_id: 8GUjDW
version_id: gETB7Pe
url: https://semgrep.dev/playground/r/gETB7Pe/go.lang.security.audit.net.formatted-template-string.formatted-template-string
origin: community
languages:
- go
severity: WARNING
patterns:
- pattern-not: template.HTML("..." + "...")
- pattern-either:
- pattern: template.HTML($T + $X, ...)
- pattern: template.HTML(fmt.$P("...", ...), ...)
- pattern: |
$T = "..."
...
$T = $FXN(..., $T, ...)
...
template.HTML($T, ...)
- pattern: |
$T = fmt.$P("...", ...)
...
template.HTML($T, ...)
- pattern: |
$T, $ERR = fmt.$P("...", ...)
...
template.HTML($T, ...)
- pattern: |
$T = $X + $Y
...
template.HTML($T, ...)
- pattern: |-
$T = "..."
...
$OTHER, $ERR = fmt.$P(..., $T, ...)
...
template.HTML($OTHER, ...)
- id: go.lang.security.audit.net.use-tls.use-tls
pattern: http.ListenAndServe($ADDR, $HANDLER)
fix: http.ListenAndServeTLS($ADDR, certFile, keyFile, $HANDLER)
metadata:
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://golang.org/pkg/net/http/#ListenAndServeTLS
category: security
technology:
- go
confidence: MEDIUM
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/go.lang.security.audit.net.use-tls.use-tls
shortlink: https://sg.run/dKbY
semgrep.dev:
rule:
r_id: 9134
rv_id: 1262948
rule_id: PeUZ8X
version_id: JdTzxkn
url: https://semgrep.dev/playground/r/JdTzxkn/go.lang.security.audit.net.use-tls.use-tls
origin: community
message: Found an HTTP server without TLS. Use 'http.ListenAndServeTLS' instead.
See https://golang.org/pkg/net/http/#ListenAndServeTLS for more information.
languages:
- go
severity: WARNING
- id: go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf
patterns:
- pattern-inside: |
func $FUNC(..., $W http.ResponseWriter, ...) {
...
var $TEMPLATE = "..."
...
$W.Write([]byte(fmt.$PRINTF($TEMPLATE, ...)), ...)
...
}
- pattern-either:
- pattern: |
$PARAMS = r.URL.Query()
...
$DATA, $ERR := $PARAMS[...]
...
$INTERM = $ANYTHING(..., $DATA, ...)
...
$W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...)))
- pattern: |
$PARAMS = r.URL.Query()
...
$DATA, $ERR := $PARAMS[...]
...
$INTERM = $DATA[...]
...
$W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...)))
- pattern: |
$DATA, $ERR := r.URL.Query()[...]
...
$INTERM = $DATA[...]
...
$W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...)))
- pattern: |
$DATA, $ERR := r.URL.Query()[...]
...
$INTERM = $ANYTHING(..., $DATA, ...)
...
$W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...)))
- pattern: |
$PARAMS = r.URL.Query()
...
$DATA, $ERR := $PARAMS[...]
...
$W.Write([]byte(fmt.$PRINTF(..., $DATA, ...)))
message: Found data going from url query parameters into formatted data written
to ResponseWriter. This could be XSS and should not be done. If you must do this,
ensure your data is sanitized or escaped.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- go
confidence: MEDIUM
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf
shortlink: https://sg.run/Zvon
semgrep.dev:
rule:
r_id: 9135
rv_id: 1262949
rule_id: JDUyXB
version_id: 5PTo1qr
url: https://semgrep.dev/playground/r/5PTo1qr/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf
origin: community
severity: WARNING
languages:
- go
- id: java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret
message: A hard-coded credential was detected. It is not recommended to store credentials
in source-code, as this risks secrets being leaked and used by either an internal
or external malicious adversary. It is recommended to use environment variables
to securely provide credentials or retrieve credentials from a secure vault or
HSM (Hardware Security Module).
metadata:
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
technology:
- java
- secrets
- jwt
category: security
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret
shortlink: https://sg.run/RoDK
semgrep.dev:
rule:
r_id: 9149
rv_id: 1262980
rule_id: oqUeAn
version_id: d6Tyx8j
url: https://semgrep.dev/playground/r/d6Tyx8j/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret
origin: community
languages:
- java
severity: WARNING
patterns:
- pattern-either:
- pattern: |
(Algorithm $ALG) = $ALGO.$HMAC("$Y");
- pattern: |
$SECRET = "$Y";
...
(Algorithm $ALG) = $ALGO.$HMAC($SECRET);
- pattern: |
class $CLASS {
...
$TYPE $SECRET = "$Y";
...
$RETURNTYPE $FUNC (...) {
...
(Algorithm $ALG) = $ALGO.$HMAC($SECRET);
...
}
...
}
- focus-metavariable: $Y
- metavariable-regex:
metavariable: $HMAC
regex: (HMAC384|HMAC256|HMAC512)
- id: java.java-jwt.security.jwt-none-alg.java-jwt-none-alg
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
assumes the integrity of the token has already been verified. This would allow
a malicious actor to forge a JWT token that will automatically be verified. Do
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
category: security
technology:
- jwt
confidence: HIGH
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg
shortlink: https://sg.run/Av14
semgrep.dev:
rule:
r_id: 9150
rv_id: 1262981
rule_id: zdUkzR
version_id: ZRTKADq
url: https://semgrep.dev/playground/r/ZRTKADq/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg
origin: community
languages:
- java
severity: ERROR
pattern-either:
- pattern: |
$JWT.sign(com.auth0.jwt.algorithms.Algorithm.none());
- pattern: |
$NONE = com.auth0.jwt.algorithms.Algorithm.none();
...
$JWT.sign($NONE);
- pattern: |-
class $CLASS {
...
$TYPE $NONE = com.auth0.jwt.algorithms.Algorithm.none();
...
$RETURNTYPE $FUNC (...) {
...
$JWT.sign($NONE);
...
}
...
}
- id: java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify
message: Detected the decoding of a JWT token without a verify step. JWT tokens
must be verified before use, otherwise the token's integrity is unknown. This
means a malicious actor could forge a JWT token with any claims. Call '.verify()'
before using the token.
metadata:
cwe:
- 'CWE-345: Insufficient Verification of Data Authenticity'
owasp:
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
category: security
technology:
- jwt
confidence: MEDIUM
references:
- https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures
subcategory:
- vuln
likelihood: LOW
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify
shortlink: https://sg.run/Bk95
semgrep.dev:
rule:
r_id: 9151
rv_id: 1262979
rule_id: pKUOE9
version_id: vdT06Lp
url: https://semgrep.dev/playground/r/vdT06Lp/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify
origin: community
languages:
- java
severity: WARNING
patterns:
- pattern: |
com.auth0.jwt.JWT.decode(...);
- pattern-not-inside: |-
class $CLASS {
...
$RETURNTYPE $FUNC (...) {
...
$VERIFIER.verify(...);
...
}
}
- id: java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal
metadata:
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN
references:
- https://www.owasp.org/index.php/Path_Traversal
category: security
technology:
- jax-rs
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal
shortlink: https://sg.run/DoWj
semgrep.dev:
rule:
r_id: 9152
rv_id: 1262984
rule_id: 2ZUb9l
version_id: 7ZTE3KW
url: https://semgrep.dev/playground/r/7ZTE3KW/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal
origin: community
message: Detected a potential path traversal. A malicious actor could control the
location of this file, to include going backwards in the directory with '../'.
To address this, ensure that user-controlled variables in file paths are sanitized.
You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...)
to only retrieve the file name from the path.
severity: WARNING
languages:
- java
pattern-either:
- pattern: |
$RETURNTYPE $FUNC (..., @PathParam(...) $TYPE $VAR, ...) {
...
new File(..., $VAR, ...);
...
}
- pattern: |-
$RETURNTYPE $FUNC (..., @javax.ws.rs.PathParam(...) $TYPE $VAR, ...) {
...
new File(..., $VAR, ...);
...
}
- id: java.jboss.security.session_sqli.find-sql-string-concatenation
message: In $METHOD, $X is used to construct a SQL query via string concatenation.
languages:
- java
severity: ERROR
pattern-either:
- pattern: |
$RETURN $METHOD(...,String $X,...){
...
Session $SESSION = ...;
...
String $QUERY = ... + $X + ...;
...
PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY);
...
ResultSet $RESULT = $PS.executeQuery();
...
}
- pattern: |
$RETURN $METHOD(...,String $X,...){
...
String $QUERY = ... + $X + ...;
...
Session $SESSION = ...;
...
PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY);
...
ResultSet $RESULT = $PS.executeQuery();
...
}
metadata:
category: security
technology:
- jboss
confidence: MEDIUM
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/java.jboss.security.session_sqli.find-sql-string-concatenation
shortlink: https://sg.run/W8kA
semgrep.dev:
rule:
r_id: 9153
rv_id: 1262986
rule_id: X5U8rQ
version_id: 8KT5r3v
url: https://semgrep.dev/playground/r/8KT5r3v/java.jboss.security.session_sqli.find-sql-string-concatenation
origin: community
- id: java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal
metadata:
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN
references:
- https://www.owasp.org/index.php/Path_Traversal
category: security
technology:
- java
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal
shortlink: https://sg.run/oxXN
semgrep.dev:
rule:
r_id: 9160
rv_id: 1263064
rule_id: NbUk7X
version_id: zyTb2rq
url: https://semgrep.dev/playground/r/zyTb2rq/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal
origin: community
message: Detected a potential path traversal. A malicious actor could control the
location of this file, to include going backwards in the directory with '../'.
To address this, ensure that user-controlled variables in file paths are sanitized.
You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...)
to only retrieve the file name from the path.
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
(HttpServletRequest $REQ)
- patterns:
- pattern-inside: |
(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);
...
for (javax.servlet.http.Cookie $COOKIE: $COOKIES) {
...
}
- pattern: |
$COOKIE.getValue(...)
- patterns:
- pattern-inside: |
$TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(...);
...
- pattern: |
$PARAM = $VALS[$INDEX];
pattern-sanitizers:
- pattern: org.apache.commons.io.FilenameUtils.getName(...)
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
(java.io.File $FILE) = ...
- pattern: |
(java.io.FileOutputStream $FOS) = ...
- pattern: |
new java.io.FileInputStream(...)
severity: ERROR
languages:
- java
- id: java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization
severity: WARNING
languages:
- java
metadata:
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.3 Insecue Deserialization
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
version: '4'
references:
- https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities-wp.pdf
category: security
technology:
- java
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization
shortlink: https://sg.run/zvO1
semgrep.dev:
rule:
r_id: 9161
rv_id: 1263065
rule_id: kxUk12
version_id: pZT03A1
url: https://semgrep.dev/playground/r/pZT03A1/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization
origin: community
message: JMS Object messages depend on Java Serialization for marshalling/unmarshalling
of the message payload when ObjectMessage.getObject() is called. Deserialization
of untrusted data can lead to security flaws; a remote attacker could via a crafted
JMS ObjectMessage to execute arbitrary code with the permissions of the application
listening/consuming JMS Messages. In this case, the JMS MessageListener consume
an ObjectMessage type received inside the onMessage method, which may lead to
arbitrary code execution when calling the $Y.getObject method.
patterns:
- pattern-inside: |
public class $JMS_LISTENER implements MessageListener {
...
public void onMessage(Message $JMS_MSG) {
...
}
}
- pattern-either:
- pattern-inside: $X = $Y.getObject(...);
- pattern-inside: $X = ($Z) $Y.getObject(...);
- id: java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss
message: 'Cross-site scripting detected in HttpServletResponse writer with variable
''$VAR''. User input was detected going directly from the HttpServletRequest into
output. Ensure your data is properly encoded using org.owasp.encoder.Encode.forHtml:
''Encode.forHtml($VAR)''.'
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_SERVLET
category: security
technology:
- java
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss
shortlink: https://sg.run/pxjN
semgrep.dev:
rule:
r_id: 9162
rv_id: 1263066
rule_id: wdUJOk
version_id: 2KTv2EG
url: https://semgrep.dev/playground/r/2KTv2EG/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss
origin: community
severity: ERROR
patterns:
- pattern-inside: $TYPE $FUNC(..., HttpServletResponse $RESP, ...) { ... }
- pattern-inside: $VAR = $REQ.getParameter(...); ...
- pattern-either:
- pattern: $RESP.getWriter(...).write(..., $VAR, ...);
- pattern: |
$WRITER = $RESP.getWriter(...);
...
$WRITER.write(..., $VAR, ...);
languages:
- java
- id: java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe
severity: WARNING
metadata:
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.2 Insecue XML Deserialization
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
version: '4'
references:
- https://semgrep.dev/blog/2022/xml-security-in-java
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
- https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf
- https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#xmlinputfactory-a-stax-parser
category: security
technology:
- java
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe
shortlink: https://sg.run/XBwA
semgrep.dev:
rule:
r_id: 9164
rv_id: 1263069
rule_id: OrU35O
version_id: 1QTypQZ
url: https://semgrep.dev/playground/r/1QTypQZ/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe
origin: community
message: XML external entities are not explicitly disabled for this XMLInputFactory.
This could be vulnerable to XML external entity vulnerabilities. Explicitly disable
external entities by setting "javax.xml.stream.isSupportingExternalEntities" to
false.
patterns:
- pattern-not-inside: |
$METHOD(...) {
...
$XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false);
...
}
- pattern-not-inside: |
$METHOD(...) {
...
$XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, false);
...
}
- pattern-not-inside: |
$METHOD(...) {
...
$XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", Boolean.FALSE);
...
}
- pattern-not-inside: |
$METHOD(...) {
...
$XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, Boolean.FALSE);
...
}
- pattern-either:
- pattern: javax.xml.stream.XMLInputFactory.newFactory(...)
- pattern: new XMLInputFactory(...)
languages:
- java
- id: java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BLOWFISH_KEY_SIZE
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- audit
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size
shortlink: https://sg.run/9o74
semgrep.dev:
rule:
r_id: 9167
rv_id: 1262989
rule_id: d8UjJ3
version_id: 3ZT4X2r
url: https://semgrep.dev/playground/r/3ZT4X2r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size
origin: community
message: Using less than 128 bits for Blowfish is considered insecure. Use 128 bits
or more, or switch to use AES instead.
severity: WARNING
languages:
- java
patterns:
- pattern: |
$KEYGEN = KeyGenerator.getInstance("Blowfish");
...
$KEYGEN.init($SIZE);
- metavariable-comparison:
metavariable: $SIZE
comparison: $SIZE < 128
- id: java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle
message: Using CBC with PKCS5Padding is susceptible to padding oracle attacks. A
malicious actor could discern the difference between plaintext with valid or invalid
padding. Further, CBC mode does not include any integrity checks. Use 'AES/GCM/NoPadding'
instead.
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PADDING_ORACLE
references:
- https://capec.mitre.org/data/definitions/463.html
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes
- https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY
category: security
technology:
- java
subcategory:
- audit
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle
shortlink: https://sg.run/ydxr
semgrep.dev:
rule:
r_id: 9168
rv_id: 1262990
rule_id: ZqU5oD
version_id: 44TEjbE
url: https://semgrep.dev/playground/r/44TEjbE/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle
origin: community
severity: WARNING
fix: |
"AES/GCM/NoPadding"
languages:
- java
patterns:
- pattern-inside: Cipher.getInstance("=~/.*\/CBC\/PKCS5Padding/")
- pattern: |
"=~/.*\/CBC\/PKCS5Padding/"
- id: java.lang.security.audit.crlf-injection-logs.crlf-injection-logs
message: When data from an untrusted source is put into a logger and not neutralized
correctly, an attacker could forge log entries or include malicious content.
metadata:
cwe:
- 'CWE-93: Improper Neutralization of CRLF Sequences (''CRLF Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#CRLF_INJECTION_LOGS
category: security
technology:
- java
references:
- https://owasp.org/Top10/A03_2021-Injection
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs
shortlink: https://sg.run/wek0
semgrep.dev:
rule:
r_id: 9173
rv_id: 1262995
rule_id: 8GUjwW
version_id: RGT0LEr
url: https://semgrep.dev/playground/r/RGT0LEr/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs
origin: community
severity: WARNING
languages:
- java
patterns:
- pattern-either:
- patterns:
- pattern-inside: |
class $CLASS {
...
Logger $LOG = ...;
...
}
- pattern-either:
- pattern-inside: |
$X $METHOD(...,HttpServletRequest $REQ,...) {
...
}
- pattern-inside: |
$X $METHOD(...,ServletRequest $REQ,...) {
...
}
- pattern-inside: |
$X $METHOD(...) {
...
HttpServletRequest $REQ = ...;
...
}
- pattern-inside: |
$X $METHOD(...) {
...
ServletRequest $REQ = ...;
...
}
- pattern-inside: |
$X $METHOD(...) {
...
Logger $LOG = ...;
...
HttpServletRequest $REQ = ...;
...
}
- pattern-inside: |
$X $METHOD(...) {
...
Logger $LOG = ...;
...
ServletRequest $REQ = ...;
...
}
- pattern-either:
- pattern: |
String $VAL = $REQ.getParameter(...);
...
$LOG.$LEVEL(<... $VAL ...>);
- pattern: |
String $VAL = $REQ.getParameter(...);
...
$LOG.log($LEVEL,<... $VAL ...>);
- pattern: |
$LOG.$LEVEL(<... $REQ.getParameter(...) ...>);
- pattern: |
$LOG.log($LEVEL,<... $REQ.getParameter(...) ...>);
- id: java.lang.security.audit.formatted-sql-string.formatted-sql-string
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.5 Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
- https://docs.oracle.com/javase/tutorial/jdbc/basics/prepared.html#create_ps
- https://software-security.sans.org/developer-how-to/fix-sql-injection-in-java-using-prepared-callable-statement
category: security
technology:
- java
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/java.lang.security.audit.formatted-sql-string.formatted-sql-string
shortlink: https://sg.run/OPXp
semgrep.dev:
rule:
r_id: 9175
rv_id: 1409389
rule_id: QrUzxR
version_id: ExTeyBP
url: https://semgrep.dev/playground/r/ExTeyBP/java.lang.security.audit.formatted-sql-string.formatted-sql-string
origin: community
options:
taint_assume_safe_numbers: true
taint_assume_safe_booleans: true
message: Detected a formatted string in a SQL statement. This could lead to SQL
injection if variables in the SQL statement are not properly sanitized. Use a
prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement
using 'connection.prepareStatement'.
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
(HttpServletRequest $REQ)
- patterns:
- pattern-inside: |
$ANNOT $FUNC (..., $INPUT, ...) {
...
}
- pattern: (String $INPUT)
- focus-metavariable: $INPUT
label: INPUT
- patterns:
- pattern-either:
- pattern: $X + $INPUT
- pattern: $X += $INPUT
- pattern: String.format(..., $INPUT, ...)
- pattern: String.join(..., $INPUT, ...)
- pattern: (String $STR).concat($INPUT)
- pattern: $INPUT.concat(...)
- patterns:
- pattern-either:
- pattern: $STRB.append($INPUT)
- pattern: new $STRB(..., $INPUT, ...)
- metavariable-type:
metavariable: $STRB
type: StringBuilder
label: CONCAT
requires: INPUT
pattern-propagators:
- pattern: (StringBuffer $S).append($X)
from: $X
to: $S
- pattern: (StringBuilder $S).append($X)
from: $X
to: $S
pattern-sinks:
- patterns:
- pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE *$/" ...>)
- pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE %s$/" ...>)
- pattern-either:
- pattern: (Statement $S).$SQLFUNC(...)
- pattern: (PreparedStatement $P).$SQLFUNC(...)
- pattern: (Connection $C).createStatement(...).$SQLFUNC(...)
- pattern: (Connection $C).prepareStatement(...).$SQLFUNC(...)
- pattern: (EntityManager $EM).$SQLFUNC(...)
- metavariable-regex:
metavariable: $SQLFUNC
regex: execute|executeQuery|createQuery|query|addBatch|nativeSQL|create|prepare
requires: CONCAT
pattern-sanitizers:
- patterns:
- pattern: (CriteriaBuilder $CB).$ANY(...)
severity: ERROR
languages:
- java
- id: java.lang.security.audit.http-response-splitting.http-response-splitting
metadata:
cwe:
- 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP
Request/Response Splitting'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTP_RESPONSE_SPLITTING
references:
- https://www.owasp.org/index.php/HTTP_Response_Splitting
category: security
technology:
- java
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/java.lang.security.audit.http-response-splitting.http-response-splitting
shortlink: https://sg.run/eL0l
semgrep.dev:
rule:
r_id: 9176
rv_id: 1263023
rule_id: 3qUPyK
version_id: X0Tzykw
url: https://semgrep.dev/playground/r/X0Tzykw/java.lang.security.audit.http-response-splitting.http-response-splitting
origin: community
message: Older Java application servers are vulnerable to HTTP response splitting,
which may occur if an HTTP request can be injected with CRLF characters. This
finding is reported for completeness; it is recommended to ensure your environment
is not affected by testing this yourself.
severity: INFO
languages:
- java
pattern-either:
- pattern: |
$VAR = $REQ.getParameter(...);
...
$COOKIE = new Cookie(..., $VAR, ...);
...
$RESP.addCookie($COOKIE, ...);
- patterns:
- pattern-inside: |
$RETTYPE $FUNC(...,@PathVariable $TYPE $VAR, ...) {
...
}
- pattern: |
$COOKIE = new Cookie(..., $VAR, ...);
...
$RESP.addCookie($COOKIE, ...);
- id: java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection
metadata:
cwe:
- 'CWE-297: Improper Validation of Certificate with Host Mismatch'
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_SMTP_SSL
category: security
technology:
- java
references:
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection
shortlink: https://sg.run/vzN4
semgrep.dev:
rule:
r_id: 9177
rv_id: 1263024
rule_id: 4bUkrW
version_id: jQTn5Dv
url: https://semgrep.dev/playground/r/jQTn5Dv/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection
origin: community
message: Insecure SMTP connection detected. This connection will trust any SSL certificate.
Enable certificate verification by setting 'email.setSSLCheckServerIdentity(true)'.
severity: WARNING
patterns:
- pattern-not-inside: |
$EMAIL.setSSLCheckServerIdentity(true);
...
- pattern-inside: |
$EMAIL = new SimpleEmail(...);
...
- pattern: $EMAIL.send(...);
languages:
- java
- id: java.lang.security.audit.unvalidated-redirect.unvalidated-redirect
message: Application redirects to a destination URL specified by a user-supplied
parameter that is not validated. This could direct users to malicious locations.
Consider using an allowlist to validate URLs.
metadata:
cwe:
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.1.5 Open Redirect
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation-requirements
version: '4'
category: security
technology:
- java
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
subcategory:
- vuln
impact: LOW
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Open Redirect
source: https://semgrep.dev/r/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect
shortlink: https://sg.run/Q51P
semgrep.dev:
rule:
r_id: 9186
rv_id: 1263048
rule_id: WAUo0p
version_id: PkTR329
url: https://semgrep.dev/playground/r/PkTR329/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect
origin: community
severity: WARNING
languages:
- java
pattern-either:
- pattern: |
$X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) {
...
$RES.sendRedirect($URL);
...
}
- pattern: |
$X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) {
...
$RES.sendRedirect($URL);
...
}
- pattern: |
$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {
...
String $URL = $REQ.getParameter(...);
...
$RES.sendRedirect($URL);
...
}
- pattern: |
$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {
...
String $URL = $REQ.getParameter(...);
...
$RES.sendRedirect($URL);
...
}
- pattern: |
$X $METHOD(...,String $URL,...) {
...
HttpServletResponse $RES = ...;
...
$RES.sendRedirect($URL);
...
}
- pattern: |
$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {
...
$RES.sendRedirect($REQ.getParameter(...));
...
}
- pattern: |
$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {
...
$RES.sendRedirect($REQ.getParameter(...));
...
}
- pattern: |
$X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) {
...
$RES.addHeader("Location",$URL);
...
}
- pattern: |
$X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) {
...
$RES.addHeader("Location",$URL);
...
}
- pattern: |
$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {
...
String $URL = $REQ.getParameter(...);
...
$RES.addHeader("Location",$URL);
...
}
- pattern: |
$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {
...
String $URL = $REQ.getParameter(...);
...
$RES.addHeader("Location",$URL);
...
}
- pattern: |
$X $METHOD(...,String $URL,...) {
...
HttpServletResponse $RES = ...;
...
$RES.addHeader("Location",$URL);
...
}
- pattern: |
$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {
...
$RES.addHeader("Location",$REQ.getParameter(...));
...
}
- pattern: |-
$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {
...
$RES.addHeader("Location",$REQ.getParameter(...));
...
}
- id: java.lang.security.audit.weak-ssl-context.weak-ssl-context
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source_rule_url: https://find-sec-bugs.github.io/bugs.htm#SSL_CONTEXT
references:
- https://tools.ietf.org/html/rfc7568
- https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html
category: security
technology:
- java
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.weak-ssl-context.weak-ssl-context
shortlink: https://sg.run/4x7E
semgrep.dev:
rule:
r_id: 9188
rv_id: 1263050
rule_id: KxUb1k
version_id: 5PTo1rW
url: https://semgrep.dev/playground/r/5PTo1rW/java.lang.security.audit.weak-ssl-context.weak-ssl-context
origin: community
message: An insecure SSL context was detected. TLS versions 1.0, 1.1, and all SSL
versions are considered weak encryption and are deprecated. Use SSLContext.getInstance("TLSv1.2")
for the best security.
severity: WARNING
languages:
- java
patterns:
- pattern-not: SSLContext.getInstance("TLSv1.3")
- pattern-not: SSLContext.getInstance("TLSv1.2")
- pattern: SSLContext.getInstance("...")
fix-regex:
regex: (.*?)\.getInstance\(.*?\)
replacement: \1.getInstance("TLSv1.2")
- id: java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated
message: DES is considered deprecated. AES is the recommended cipher. Upgrade to
use AES. See https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard
for more information.
metadata:
functional-categories:
- crypto::search::symmetric-algorithm::javax.crypto
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DES_USAGE
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
references:
- https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
category: security
technology:
- java
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated
shortlink: https://sg.run/5Q73
semgrep.dev:
rule:
r_id: 9191
rv_id: 1262996
rule_id: PeUZNg
version_id: A8TgdEn
url: https://semgrep.dev/playground/r/A8TgdEn/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated
origin: community
severity: WARNING
patterns:
- pattern-either:
- pattern-inside: $CIPHER.getInstance("=~/DES/.*/")
- pattern-inside: $CIPHER.getInstance("DES")
- pattern-either:
- pattern: |
"=~/DES/.*/"
- pattern: |
"DES"
fix: |
"AES/GCM/NoPadding"
languages:
- java
- kt
- id: java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated
message: Triple DES (3DES or DESede) is considered deprecated. AES is the recommended
cipher. Upgrade to use AES.
metadata:
functional-categories:
- crypto::search::symmetric-algorithm::javax.crypto
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#TDES_USAGE
references:
- https://csrc.nist.gov/News/2017/Update-to-Current-Use-and-Deprecation-of-TDEA
category: security
technology:
- java
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated
shortlink: https://sg.run/Geqn
semgrep.dev:
rule:
r_id: 9192
rv_id: 1262997
rule_id: JDUy8J
version_id: BjTkZyQ
url: https://semgrep.dev/playground/r/BjTkZyQ/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated
origin: community
severity: WARNING
patterns:
- pattern-either:
- pattern: |
$CIPHER.getInstance("=~/DESede.*/")
- pattern: |
$CRYPTO.KeyGenerator.getInstance("DES")
languages:
- java
- kt
- id: java.lang.security.audit.crypto.ecb-cipher.ecb-cipher
metadata:
functional-categories:
- crypto::search::mode::javax.crypto
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher
shortlink: https://sg.run/Ro9K
semgrep.dev:
rule:
r_id: 9193
rv_id: 1262998
rule_id: 5rUOb6
version_id: DkTRbwL
url: https://semgrep.dev/playground/r/DkTRbwL/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher
origin: community
message: Cipher in ECB mode is detected. ECB mode produces the same output for the
same input each time which allows an attacker to intercept and replay the data.
Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY.
severity: WARNING
languages:
- java
patterns:
- pattern: |
Cipher $VAR = $CIPHER.getInstance($MODE);
- metavariable-regex:
metavariable: $MODE
regex: .*ECB.*
- id: java.lang.security.audit.crypto.no-null-cipher.no-null-cipher
patterns:
- pattern-either:
- pattern: new NullCipher(...);
- pattern: new javax.crypto.NullCipher(...);
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher
shortlink: https://sg.run/AvA4
semgrep.dev:
rule:
r_id: 9194
rv_id: 1263001
rule_id: GdU7pw
version_id: K3TKkgB
url: https://semgrep.dev/playground/r/K3TKkgB/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher
origin: community
message: 'NullCipher was detected. This will not encrypt anything; the cipher text
will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING").
See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for
more information.'
severity: WARNING
languages:
- java
- id: java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector
message: Initialization Vectors (IVs) for block ciphers should be randomly generated
each time they are used. Using a static IV means the same plaintext encrypts to
the same ciphertext every time, weakening the strength of the encryption.
metadata:
cwe:
- 'CWE-329: Generation of Predictable IV with CBC Mode'
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#STATIC_IV
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
references:
- https://cwe.mitre.org/data/definitions/329.html
category: security
technology:
- java
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector
shortlink: https://sg.run/BkB5
semgrep.dev:
rule:
r_id: 9195
rv_id: 1263002
rule_id: ReUgj1
version_id: qkTR7vP
url: https://semgrep.dev/playground/r/qkTR7vP/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector
origin: community
severity: WARNING
languages:
- java
pattern-either:
- pattern: |
byte[] $IV = {
...
};
...
new IvParameterSpec($IV, ...);
- pattern: |
class $CLASS {
byte[] $IV = {
...
};
...
$METHOD(...) {
...
new IvParameterSpec($IV, ...);
...
}
}
- id: java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding
metadata:
functional-categories:
- crypto::search::mode::javax.crypto
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_NO_PADDING
references:
- https://rdist.root.org/2009/10/06/why-rsa-encryption-padding-is-critical/
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
category: security
technology:
- java
- kotlin
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding
shortlink: https://sg.run/DoOj
semgrep.dev:
rule:
r_id: 9196
rv_id: 1263003
rule_id: AbUzoj
version_id: l4TJRpK
url: https://semgrep.dev/playground/r/l4TJRpK/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding
origin: community
message: Using RSA without OAEP mode weakens the encryption.
severity: WARNING
languages:
- java
- kt
pattern: $CIPHER.getInstance("=~/RSA/[Nn][Oo][Nn][Ee]/NoPadding/")
- id: java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket
metadata:
functional-categories:
- net::search::crypto-config::java.net
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket
shortlink: https://sg.run/W8zA
semgrep.dev:
rule:
r_id: 9197
rv_id: 1263008
rule_id: BYUN3X
version_id: RGT0LEj
url: https://semgrep.dev/playground/r/RGT0LEj/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket
origin: community
message: Detected use of a Java socket that is not encrypted. As a result, the traffic
could be read by an attacker intercepting the network traffic. Use an SSLSocket
created by 'SSLSocketFactory' or 'SSLServerSocketFactory' instead.
severity: WARNING
languages:
- java
pattern-either:
- pattern: new ServerSocket(...)
- pattern: new Socket(...)
- id: java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key
message: RSA keys should be at least 2048 bits based on NIST recommendation.
languages:
- java
severity: WARNING
metadata:
functional-categories:
- crypto::search::key-length::java.security
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
category: security
technology:
- java
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key
shortlink: https://sg.run/4x6x
semgrep.dev:
rule:
r_id: 9200
rv_id: 1263019
rule_id: 0oU5P5
version_id: o5TbDLY
url: https://semgrep.dev/playground/r/o5TbDLY/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key
origin: community
patterns:
- pattern: |
KeyPairGenerator $KEY = $G.getInstance("RSA");
...
$KEY.initialize($BITS);
- metavariable-comparison:
metavariable: $BITS
comparison: $BITS < 2048
- id: java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer
message: Detected a request with potential user-input going into a OutputStream
or Writer object. This bypasses any view or template environments, including HTML
escaping, which may expose this application to cross-site scripting (XSS) vulnerabilities.
Consider using a view technology such as JavaServer Faces (JSFs) which automatically
escapes HTML views.
severity: WARNING
options:
interfile: true
metadata:
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
category: security
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
cwe2021-top25: true
cwe2022-top25: true
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://www3.ntu.edu.sg/home/ehchua/programming/java/JavaServerFaces.html
subcategory:
- vuln
technology:
- java
- servlets
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer
shortlink: https://sg.run/KlRL
semgrep.dev:
rule:
r_id: 9211
rv_id: 1263055
rule_id: j2Uv7B
version_id: DkTRbXy
url: https://semgrep.dev/playground/r/DkTRbXy/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer
origin: community
languages:
- java
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
(HttpServletRequest $REQ).$REQFUNC(...)
- pattern: "(ServletRequest $REQ).$REQFUNC(...) \n"
- metavariable-regex:
metavariable: $REQFUNC
regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString)
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
(HttpServletResponse $RESPONSE).getWriter(...).$WRITE(...)
- pattern: |
(HttpServletResponse $RESPONSE).getOutputStream(...).$WRITE(...)
- pattern: |
(java.io.PrintWriter $WRITER).$WRITE(...)
- pattern: |
(PrintWriter $WRITER).$WRITE(...)
- pattern: |
(javax.servlet.ServletOutputStream $WRITER).$WRITE(...)
- pattern: |
(ServletOutputStream $WRITER).$WRITE(...)
- pattern: |
(java.io.OutputStream $WRITER).$WRITE(...)
- pattern: |
(OutputStream $WRITER).$WRITE(...)
pattern-sanitizers:
- pattern-either:
- pattern: Encode.forHtml(...)
- pattern: (PolicyFactory $POLICY).sanitize(...)
- pattern: (AntiSamy $AS).scan(...)
- pattern: JSoup.clean(...)
- pattern: org.apache.commons.lang.StringEscapeUtils.escapeHtml(...)
- pattern: org.springframework.web.util.HtmlUtils.htmlEscape(...)
- pattern: org.owasp.esapi.ESAPI.encoder().encodeForHTML(...)
- id: java.spring.security.audit.spring-sqli.spring-sqli
mode: taint
pattern-sources:
- patterns:
- pattern: $ARG
- pattern-inside: |
public $T $M (..., String $ARG,...){...}
pattern-sanitizers:
- not_conflicting: true
pattern-either:
- patterns:
- focus-metavariable: $A
- pattern-inside: |
new $TYPE(...,$A,...);
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- focus-metavariable: $A
- pattern: |
new PreparedStatementCreatorFactory($A,...);
- patterns:
- focus-metavariable: $A
- pattern: |
(JdbcTemplate $T).$M($A,...)
- patterns:
- pattern: (String $A)
- pattern-inside: |
(JdbcTemplate $T).batchUpdate(...)
- patterns:
- focus-metavariable: $A
- pattern: |
NamedParameterBatchUpdateUtils.$M($A,...)
- patterns:
- focus-metavariable: $A
- pattern: |
BatchUpdateUtils.$M($A,...)
message: Detected a string argument from a public method contract in a raw SQL statement.
This could lead to SQL injection if variables in the SQL statement are not properly
sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You
can obtain a PreparedStatement using 'connection.prepareStatement'.
languages:
- java
severity: WARNING
options:
taint_assume_safe_numbers: true
taint_assume_safe_booleans: true
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
category: security
technology:
- spring
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/java.spring.security.audit.spring-sqli.spring-sqli
shortlink: https://sg.run/1Z3x
semgrep.dev:
rule:
r_id: 9222
rv_id: 1263082
rule_id: eqU8N2
version_id: ZRTKAWW
url: https://semgrep.dev/playground/r/ZRTKAWW/java.spring.security.audit.spring-sqli.spring-sqli
origin: community
- id: java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect
message: Application redirects a user to a destination URL specified by a user supplied
parameter that is not validated.
metadata:
cwe:
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT
category: security
technology:
- spring
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Open Redirect
source: https://semgrep.dev/r/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect
shortlink: https://sg.run/9oXz
semgrep.dev:
rule:
r_id: 9223
rv_id: 1263083
rule_id: v8Un7w
version_id: nWT2Lk0
url: https://semgrep.dev/playground/r/nWT2Lk0/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect
origin: community
severity: WARNING
languages:
- java
pattern-either:
- pattern: |
$X $METHOD(...,String $URL,...) {
return "redirect:" + $URL;
}
- pattern: |
$X $METHOD(...,String $URL,...) {
...
String $REDIR = "redirect:" + $URL;
...
return $REDIR;
...
}
- pattern: |
$X $METHOD(...,String $URL,...) {
...
new ModelAndView("redirect:" + $URL);
...
}
- pattern: |-
$X $METHOD(...,String $URL,...) {
...
String $REDIR = "redirect:" + $URL;
...
new ModelAndView($REDIR);
...
}
- id: javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled
message: $sceProvider is set to false. Disabling Strict Contextual escaping (SCE)
in an AngularJS application could provide additional attack surface for XSS vulnerabilities.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
references:
- https://docs.angularjs.org/api/ng/service/$sce
- https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf
category: security
technology:
- angular
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled
shortlink: https://sg.run/N4DG
semgrep.dev:
rule:
r_id: 9227
rv_id: 1263094
rule_id: EwU20Z
version_id: 5PTo1EW
url: https://semgrep.dev/playground/r/5PTo1EW/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled
origin: community
languages:
- javascript
- typescript
severity: ERROR
pattern: |
$sceProvider.enabled(false);
- id: javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method
message: The use of $sce.trustAs can be dangerous if unsanitized user input flows
through this API.
metadata:
references:
- https://docs.angularjs.org/api/ng/service/$sce
- https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf
category: security
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
technology:
- angular
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method
shortlink: https://sg.run/OPW2
semgrep.dev:
rule:
r_id: 9231
rv_id: 1263098
rule_id: gxU1QX
version_id: BjTkZv0
url: https://semgrep.dev/playground/r/BjTkZv0/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-inside: |
app.controller(..., function($scope,$sce) {
...
});
- pattern: $scope.$X
pattern-sinks:
- pattern: $sce.trustAs(...)
- pattern: $sce.trustAsHtml(...)
- id: javascript.browser.security.open-redirect.js-open-redirect
message: The application accepts potentially user-controlled input `$PROP` which
can control the location of the current window context. This can lead two types
of vulnerabilities open-redirection and Cross-Site-Scripting (XSS) with JavaScript
URIs. It is recommended to validate user-controllable input before allowing it
to control the redirection.
options:
interfile: true
metadata:
interfile: true
cwe:
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.1 Insecue Redirect
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation
version: '4'
category: security
confidence: HIGH
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html
technology:
- browser
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Open Redirect
source: https://semgrep.dev/r/javascript.browser.security.open-redirect.js-open-redirect
shortlink: https://sg.run/3xRe
semgrep.dev:
rule:
r_id: 9243
rv_id: 1263122
rule_id: WAUopl
version_id: pZT03x0
url: https://semgrep.dev/playground/r/pZT03x0/javascript.browser.security.open-redirect.js-open-redirect
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
new URLSearchParams($WINDOW. ... .location.search).get('...')
- pattern: |
new URLSearchParams(location.search).get('...')
- pattern: |
new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...')
- pattern: |
new URLSearchParams(location.hash.substring(1)).get('...')
- patterns:
- pattern-either:
- pattern-inside: |
$PROPS = new URLSearchParams($WINDOW. ... .location.search)
...
- pattern-inside: |
$PROPS = new URLSearchParams(location.search)
...
- pattern-inside: |
$PROPS = new URLSearchParams($WINDOW. ... .location.hash.substring(1))
...
- pattern-inside: |
$PROPS = new URLSearchParams(location.hash.substring(1))
...
- pattern: $PROPS.get('...')
- patterns:
- pattern-either:
- pattern-inside: |
$PROPS = new URL($WINDOW. ... .location.href)
...
- pattern-inside: |
$PROPS = new URL(location.href)
...
- pattern: $PROPS.searchParams.get('...')
- patterns:
- pattern-either:
- pattern: |
new URL($WINDOW. ... .location.href).searchParams.get('...')
- pattern: |
new URL(location.href).searchParams.get('...')
pattern-sinks:
- patterns:
- pattern-either:
- pattern: location.href = $SINK
- pattern: $THIS. ... .location.href = $SINK
- pattern: location.replace($SINK)
- pattern: $THIS. ... .location.replace($SINK)
- pattern: location = $SINK
- pattern: $WINDOW. ... .location = $SINK
- focus-metavariable: $SINK
- metavariable-pattern:
patterns:
- pattern-not: |
"..." + $VALUE
- pattern-not: |
`...${$VALUE}`
metavariable: $SINK
- id: javascript.browser.security.raw-html-concat.raw-html-concat
message: User controlled data in a HTML string may result in XSS
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/www-community/attacks/xss/
category: security
technology:
- browser
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/javascript.browser.security.raw-html-concat.raw-html-concat
shortlink: https://sg.run/4xAx
semgrep.dev:
rule:
r_id: 9244
rv_id: 1263123
rule_id: 0oU5b5
version_id: 2KTv2wp
url: https://semgrep.dev/playground/r/2KTv2wp/javascript.browser.security.raw-html-concat.raw-html-concat
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: location.href
- pattern: location.hash
- pattern: location.search
- pattern: $WINDOW. ... .location.href
- pattern: $WINDOW. ... .location.hash
- pattern: $WINDOW. ... .location.search
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: $STRING + $EXPR
- pattern-not: $STRING + "..."
- metavariable-pattern:
patterns:
- pattern: <$TAG ...
- pattern-not: <$TAG ...>...</$TAG>...
metavariable: $STRING
language: generic
- patterns:
- pattern: $EXPR + $STRING
- pattern-not: '"..." + $STRING'
- metavariable-pattern:
patterns:
- pattern: '... </$TAG'
metavariable: $STRING
language: generic
- patterns:
- pattern: '[..., $STRING, ...].join(...)'
- metavariable-pattern:
patterns:
- pattern: <$TAG ...
metavariable: $STRING
language: generic
- patterns:
- pattern: '[..., $STRING, ...].join(...)'
- metavariable-pattern:
patterns:
- pattern: '... </$TAG'
metavariable: $STRING
language: generic
- patterns:
- pattern: $VAR += $STRING
- metavariable-pattern:
patterns:
- pattern: <$TAG ...
metavariable: $STRING
language: generic
- patterns:
- pattern: $VAR += $STRING
- metavariable-pattern:
patterns:
- pattern: '... </$TAG'
metavariable: $STRING
language: generic
pattern-sanitizers:
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
import * as $S from "underscore.string"
...
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
$S = require("underscore.string")
...
- pattern-either:
- pattern: $S.escapeHTML(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "dompurify"
...
- pattern-inside: |
import { ..., $S,... } from "dompurify"
...
- pattern-inside: |
import * as $S from "dompurify"
...
- pattern-inside: |
$S = require("dompurify")
...
- pattern-inside: |
import $S from "isomorphic-dompurify"
...
- pattern-inside: |
import * as $S from "isomorphic-dompurify"
...
- pattern-inside: |
$S = require("isomorphic-dompurify")
...
- pattern-either:
- patterns:
- pattern-inside: |
$VALUE = $S(...)
...
- pattern: $VALUE.sanitize(...)
- patterns:
- pattern-inside: |
$VALUE = $S.sanitize
...
- pattern: $S(...)
- pattern: $S.sanitize(...)
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'xss';
...
- pattern-inside: |
import * as $S from 'xss';
...
- pattern-inside: |
$S = require("xss")
...
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'sanitize-html';
...
- pattern-inside: |
import * as $S from "sanitize-html";
...
- pattern-inside: |
$S = require("sanitize-html")
...
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
$S = new Remarkable()
...
- pattern: $S.render(...)
- id: javascript.browser.security.wildcard-postmessage-configuration.wildcard-postmessage-configuration
message: The target origin of the window.postMessage() API is set to "*". This could
allow for information disclosure due to the possibility of any origin allowed
to receive the message.
metadata:
owasp:
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
cwe:
- 'CWE-345: Insufficient Verification of Data Authenticity'
category: security
technology:
- browser
subcategory:
- audit
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
references:
- https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/javascript.browser.security.wildcard-postmessage-configuration.wildcard-postmessage-configuration
shortlink: https://sg.run/PJ4p
semgrep.dev:
rule:
r_id: 9245
rv_id: 1263125
rule_id: KxUbq4
version_id: jQTn5ND
url: https://semgrep.dev/playground/r/jQTn5ND/javascript.browser.security.wildcard-postmessage-configuration.wildcard-postmessage-configuration
origin: community
languages:
- javascript
- typescript
severity: WARNING
pattern: $OBJECT.postMessage(...,'*',...)
- id: javascript.chrome-remote-interface.security.audit.chrome-remote-interface-compilescript-injection.chrome-remote-interface-compilescript-injection
message: If unverified user data can reach the `compileScript` method it can result
in Server-Side Request Forgery vulnerabilities
metadata:
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
category: security
technology:
- chrome-remote-interface
references:
- https://github.com/cyrus-and/chrome-remote-interface
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/javascript.chrome-remote-interface.security.audit.chrome-remote-interface-compilescript-injection.chrome-remote-interface-compilescript-injection
shortlink: https://sg.run/J9kj
semgrep.dev:
rule:
r_id: 9246
rv_id: 1263126
rule_id: qNUjnb
version_id: 1QTypkQ
url: https://semgrep.dev/playground/r/1QTypkQ/javascript.chrome-remote-interface.security.audit.chrome-remote-interface-compilescript-injection.chrome-remote-interface-compilescript-injection
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-inside: function ... (..., $ARG,...) {...}
- focus-metavariable: $ARG
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
require('chrome-remote-interface');
...
- pattern-inside: |
import 'chrome-remote-interface';
...
- pattern-either:
- pattern: |
$RUNTIME.compileScript({expression: $SINK},...)
- pattern: |
$RUNTIME.evaluate({expression: $SINK},...)
- pattern: |
$PAGE.navigate({url: $SINK},...)
- pattern: |
$RUNTIME.printToPDF({headerTemplate: $SINK},...)
- pattern: |
$RUNTIME.printToPDF({footerTemplate: $SINK},...)
- pattern: |
$PAGE.setDocumentContent({html: $SINK},...)
- focus-metavariable: $SINK
- id: javascript.express.security.express-expat-xxe.express-expat-xxe
message: Make sure that unverified user data can not reach the XML Parser, as it
can result in XML External or Internal Entity (XXE) Processing vulnerabilities.
options:
interfile: true
metadata:
interfile: true
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.2 Insecue XML Deserialization
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
version: '4'
references:
- https://github.com/astro/node-expat
category: security
technology:
- express
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/javascript.express.security.express-expat-xxe.express-expat-xxe
shortlink: https://sg.run/BkXx
semgrep.dev:
rule:
r_id: 9251
rv_id: 1263164
rule_id: zdUkJl
version_id: o5TbD5l
url: https://semgrep.dev/playground/r/o5TbD5l/javascript.express.security.express-expat-xxe.express-expat-xxe
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
$XML = require('node-expat')
...
- pattern-inside: |
import $XML from 'node-expat'
...
- pattern-inside: |
import * as $XML from 'node-expat'
...
- pattern-either:
- pattern-inside: |
$PARSER = new $XML.Parser(...);
...
- pattern-either:
- pattern: $PARSER.parse($QUERY)
- pattern: $PARSER.write($QUERY)
- focus-metavariable: $QUERY
- id: javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret
message: A hard-coded credential was detected. It is not recommended to store credentials
in source-code, as this risks secrets being leaked and used by either an internal
or external malicious adversary. It is recommended to use environment variables
to securely provide credentials or retrieve credentials from a secure vault or
HSM (Hardware Security Module).
options:
interfile: true
metadata:
interfile: true
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
category: security
technology:
- express
- secrets
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret
shortlink: https://sg.run/Do1d
semgrep.dev:
rule:
r_id: 9252
rv_id: 1263166
rule_id: pKUOjy
version_id: pZT03Q0
url: https://semgrep.dev/playground/r/pZT03Q0/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret
origin: community
languages:
- javascript
- typescript
severity: WARNING
patterns:
- pattern-either:
- pattern-inside: |
$JWT = require('express-jwt');
...
- pattern-inside: |
import $JWT from 'express-jwt';
...
- pattern-inside: |
import * as $JWT from 'express-jwt';
...
- pattern-inside: |
import { ..., $JWT, ... } from 'express-jwt';
...
- pattern-either:
- pattern: |
$JWT({...,secret: "$Y",...},...)
- pattern: |
$OPTS = "$Y";
...
$JWT({...,secret: $OPTS},...);
- focus-metavariable: $Y
- id: javascript.express.security.express-phantom-injection.express-phantom-injection
message: If unverified user data can reach the `phantom` methods it can result in
Server-Side Request Forgery vulnerabilities
metadata:
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
category: security
technology:
- express
references:
- https://phantomjs.org/page-automation.html
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/javascript.express.security.express-phantom-injection.express-phantom-injection
shortlink: https://sg.run/W8BL
semgrep.dev:
rule:
r_id: 9253
rv_id: 1263167
rule_id: 2ZUbx3
version_id: 2KTv26p
url: https://semgrep.dev/playground/r/2KTv26p/javascript.express.security.express-phantom-injection.express-phantom-injection
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
require('phantom');
...
- pattern-inside: |
import 'phantom';
...
- pattern-either:
- pattern: $PAGE.open($SINK,...)
- pattern: $PAGE.setContent($SINK,...)
- pattern: $PAGE.openUrl($SINK,...)
- pattern: $PAGE.evaluateJavaScript($SINK,...)
- pattern: $PAGE.property("content",$SINK,...)
- focus-metavariable: $SINK
- id: javascript.express.security.express-puppeteer-injection.express-puppeteer-injection
message: If unverified user data can reach the `puppeteer` methods it can result
in Server-Side Request Forgery vulnerabilities
metadata:
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
category: security
technology:
- express
references:
- https://pptr.dev/api/puppeteer.page
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection
shortlink: https://sg.run/0QJB
semgrep.dev:
rule:
r_id: 9254
rv_id: 1263168
rule_id: X5U8Nz
version_id: X0TzyJY
url: https://semgrep.dev/playground/r/X0TzyJY/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
require('puppeteer');
...
- pattern-inside: |
import 'puppeteer';
...
- pattern-either:
- pattern: $PAGE.goto($SINK,...)
- pattern: $PAGE.setContent($SINK,...)
- pattern: $PAGE.evaluate($SINK,...)
- pattern: $PAGE.evaluate($CODE,$SINK,...)
- pattern: $PAGE.evaluateHandle($SINK,...)
- pattern: $PAGE.evaluateHandle($CODE,$SINK,...)
- pattern: $PAGE.evaluateOnNewDocument($SINK,...)
- pattern: $PAGE.evaluateOnNewDocument($CODE,$SINK,...)
- focus-metavariable: $SINK
- id: javascript.express.security.express-sandbox-injection.express-sandbox-code-injection
message: Make sure that unverified user data can not reach `sandbox`.
metadata:
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
category: security
technology:
- express
cwe2022-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection
shortlink: https://sg.run/KlwL
semgrep.dev:
rule:
r_id: 9255
rv_id: 1263169
rule_id: j2UvXB
version_id: jQTn59D
url: https://semgrep.dev/playground/r/jQTn59D/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-inside: |
$SANDBOX = require('sandbox');
...
- pattern-either:
- patterns:
- pattern-inside: |
$S = new $SANDBOX(...);
...
- pattern: |
$S.run(...)
- pattern: |
new $SANDBOX($OPTS).run(...)
- pattern: new $SANDBOX().run(...)
- id: javascript.express.security.express-xml2json-xxe.express-xml2json-xxe
message: Make sure that unverified user data can not reach the XML Parser, as it
can result in XML External or Internal Entity (XXE) Processing vulnerabilities
metadata:
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.2 Insecue XML Deserialization
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
version: '4'
category: security
technology:
- express
references:
- https://www.npmjs.com/package/xml2json
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe
shortlink: https://sg.run/XBD4
semgrep.dev:
rule:
r_id: 9264
rv_id: 1263174
rule_id: x8Uneb
version_id: bZT534J
url: https://semgrep.dev/playground/r/bZT534J/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
- pattern: files.$ANYTHING.data.toString('utf8')
- pattern: files.$ANYTHING['data'].toString('utf8')
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
require('xml2json');
...
- pattern-inside: |
import 'xml2json';
...
- pattern: $EXPAT.toJson($SINK,...)
- focus-metavariable: $SINK
- id: javascript.express.security.require-request.require-request
message: If an attacker controls the x in require(x) then they can cause code to
load that was not intended to run on the server.
options:
interfile: true
metadata:
interfile: true
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-706: Use of Incorrectly-Resolved Name or Reference'
source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html
category: security
technology:
- express
references:
- https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/javascript.express.security.require-request.require-request
shortlink: https://sg.run/jRbl
semgrep.dev:
rule:
r_id: 9265
rv_id: 1263177
rule_id: OrU3WK
version_id: w8TRo0d
url: https://semgrep.dev/playground/r/w8TRo0d/javascript.express.security.require-request.require-request
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern: require($SINK)
- focus-metavariable: $SINK
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name
message: "Don\u2019t use the default session cookie name Using the default session
cookie name can open your app to attacks. The security issue posed is similar
to X-Powered-By: a potential attacker can use it to fingerprint the server and
target attacks accordingly."
severity: WARNING
languages:
- javascript
- typescript
metadata:
cwe:
- 'CWE-522: Insufficiently Protected Credentials'
owasp:
- A02:2017 - Broken Authentication
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
category: security
technology:
- express
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: LOW
confidence: MEDIUM
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name
shortlink: https://sg.run/1Z5x
semgrep.dev:
rule:
r_id: 9266
rv_id: 1263130
rule_id: eqU8k2
version_id: bZT536J
url: https://semgrep.dev/playground/r/bZT536J/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name
origin: community
patterns:
- pattern-either:
- pattern-inside: |
$SESSION = require('cookie-session');
...
- pattern-inside: |
$SESSION = require('express-session');
...
- pattern: $SESSION(...)
- pattern-not-inside: $SESSION(<... {name:...} ...>,...)
- pattern-not-inside: |
$OPTS = <... {name:...} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$OPTS.name = ...;
...
$SESSION($OPTS,...);
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure
message: 'Default session middleware settings: `secure` not set. It ensures the
browser only sends the cookie over HTTPS.'
severity: WARNING
languages:
- javascript
- typescript
metadata:
cwe:
- 'CWE-522: Insufficiently Protected Credentials'
owasp:
- A02:2017 - Broken Authentication
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
category: security
technology:
- express
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: LOW
confidence: MEDIUM
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure
shortlink: https://sg.run/9oKz
semgrep.dev:
rule:
r_id: 9267
rv_id: 1263131
rule_id: v8Unzw
version_id: NdTzyrv
url: https://semgrep.dev/playground/r/NdTzyrv/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure
origin: community
patterns:
- pattern-either:
- pattern-inside: |
$SESSION = require('cookie-session');
...
- pattern-inside: |
$SESSION = require('express-session');
...
- pattern: $SESSION(...)
- pattern-not-inside: $SESSION(<... {cookie:{secure:true}} ...>,...)
- pattern-not-inside: |
$OPTS = <... {cookie:{secure:true}} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$COOKIE = <... {secure:true} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$OPTS.cookie = <... {secure:true} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$COOKIE.secure = true;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$OPTS.cookie.secure = true;
...
$SESSION($OPTS,...);
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly
message: 'Default session middleware settings: `httpOnly` not set. It ensures the
cookie is sent only over HTTP(S), not client JavaScript, helping to protect against
cross-site scripting attacks.'
severity: WARNING
languages:
- javascript
- typescript
metadata:
cwe:
- 'CWE-522: Insufficiently Protected Credentials'
owasp:
- A02:2017 - Broken Authentication
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
category: security
technology:
- express
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: LOW
confidence: MEDIUM
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly
shortlink: https://sg.run/ydBO
semgrep.dev:
rule:
r_id: 9268
rv_id: 1263132
rule_id: d8UjGo
version_id: kbTzGev
url: https://semgrep.dev/playground/r/kbTzGev/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly
origin: community
patterns:
- pattern-either:
- pattern-inside: |
$SESSION = require('cookie-session');
...
- pattern-inside: |
$SESSION = require('express-session');
...
- pattern: $SESSION(...)
- pattern-not-inside: $SESSION(<... {cookie:{httpOnly:true}} ...>,...)
- pattern-not-inside: |
$OPTS = <... {cookie:{httpOnly:true}} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$COOKIE = <... {httpOnly:true} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$OPTS.cookie = <... {httpOnly:true} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$COOKIE.httpOnly = true;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$OPTS.cookie.httpOnly = true;
...
$SESSION($OPTS,...);
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain
message: 'Default session middleware settings: `domain` not set. It indicates the
domain of the cookie; use it to compare against the domain of the server in which
the URL is being requested. If they match, then check the path attribute next.'
severity: WARNING
languages:
- javascript
- typescript
metadata:
cwe:
- 'CWE-522: Insufficiently Protected Credentials'
owasp:
- A02:2017 - Broken Authentication
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
category: security
technology:
- express
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: LOW
confidence: MEDIUM
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain
shortlink: https://sg.run/rd41
semgrep.dev:
rule:
r_id: 9269
rv_id: 1263133
rule_id: ZqU5Pn
version_id: w8TRoyd
url: https://semgrep.dev/playground/r/w8TRoyd/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain
origin: community
patterns:
- pattern-either:
- pattern-inside: |
$SESSION = require('cookie-session');
...
- pattern-inside: |
$SESSION = require('express-session');
...
- pattern: $SESSION(...)
- pattern-not-inside: $SESSION(<... {cookie:{domain:...}} ...>,...)
- pattern-not-inside: |
$OPTS = <... {cookie:{domain:...}} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$COOKIE = <... {domain:...} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$OPTS.cookie = <... {domain:...} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$COOKIE.domain = ...;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$OPTS.cookie.domain = ...;
...
$SESSION($OPTS,...);
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path
message: 'Default session middleware settings: `path` not set. It indicates the
path of the cookie; use it to compare against the request path. If this and domain
match, then send the cookie in the request.'
severity: WARNING
languages:
- javascript
- typescript
metadata:
cwe:
- 'CWE-522: Insufficiently Protected Credentials'
owasp:
- A02:2017 - Broken Authentication
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
category: security
technology:
- express
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: LOW
confidence: MEDIUM
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path
shortlink: https://sg.run/b7pd
semgrep.dev:
rule:
r_id: 9270
rv_id: 1263134
rule_id: nJUz4X
version_id: xyTjzQD
url: https://semgrep.dev/playground/r/xyTjzQD/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path
origin: community
patterns:
- pattern-either:
- pattern-inside: |
$SESSION = require('cookie-session');
...
- pattern-inside: |
$SESSION = require('express-session');
...
- pattern: $SESSION(...)
- pattern-not-inside: $SESSION(<... {cookie:{path:...}} ...>,...)
- pattern-not-inside: |
$OPTS = <... {cookie:{path:...}} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$COOKIE = <... {path:...} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$OPTS.cookie = <... {path:...} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$COOKIE.path = ...;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$OPTS.cookie.path = ...;
...
$SESSION($OPTS,...);
- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires
message: 'Default session middleware settings: `expires` not set. Use it to set
expiration date for persistent cookies.'
severity: WARNING
languages:
- javascript
- typescript
metadata:
cwe:
- 'CWE-522: Insufficiently Protected Credentials'
owasp:
- A02:2017 - Broken Authentication
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html
category: security
technology:
- express
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: LOW
confidence: MEDIUM
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires
shortlink: https://sg.run/N4eG
semgrep.dev:
rule:
r_id: 9271
rv_id: 1263135
rule_id: EwU2DZ
version_id: O9TpxRq
url: https://semgrep.dev/playground/r/O9TpxRq/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires
origin: community
patterns:
- pattern-either:
- pattern-inside: |
$SESSION = require('cookie-session');
...
- pattern-inside: |
$SESSION = require('express-session');
...
- pattern: $SESSION(...)
- pattern-not-inside: $SESSION(<... {cookie:{expires:...}} ...>,...)
- pattern-not-inside: |
$OPTS = <... {cookie:{expires:...}} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$COOKIE = <... {expires:...} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$OPTS.cookie = <... {expires:...} ...>;
...
$SESSION($OPTS,...);
- pattern-not-inside: |
$OPTS = ...;
...
$COOKIE.expires = ...;
...
$SESSION($OPTS,...);
- pattern-not-inside: |-
$OPTS = ...;
...
$OPTS.cookie.expires = ...;
...
$SESSION($OPTS,...);
- id: javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked
message: No token revoking configured for `express-jwt`. A leaked token could still
be used and unable to be revoked. Consider using function as the `isRevoked` option.
metadata:
cwe:
- 'CWE-522: Insufficiently Protected Credentials'
owasp:
- A02:2017 - Broken Authentication
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
source-rule-url: https://github.com/goldbergyoni/nodebestpractices/blob/master/sections/security/expirejwt.md
asvs:
section: 'V3: Session Management Verification Requirements'
control_id: 3.5.3 Insecure Stateless Session Tokens
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
version: '4'
category: security
technology:
- express
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked
shortlink: https://sg.run/kXNo
semgrep.dev:
rule:
r_id: 9272
rv_id: 1263137
rule_id: 7KUQ9k
version_id: vdT06Bg
url: https://semgrep.dev/playground/r/vdT06Bg/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked
origin: community
languages:
- javascript
- typescript
severity: WARNING
patterns:
- pattern-inside: |
$JWT = require('express-jwt');
...
- pattern: $JWT(...)
- pattern-not-inside: $JWT(<... {isRevoked:...} ...>,...)
- pattern-not-inside: |-
$OPTS = <... {isRevoked:...} ...>;
...
$JWT($OPTS,...);
- id: javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal
message: Possible writing outside of the destination, make sure that the target
path is nested in the intended destination
metadata:
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
category: security
references:
- https://owasp.org/www-community/attacks/Path_Traversal
technology:
- express
- node.js
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal
shortlink: https://sg.run/weRn
semgrep.dev:
rule:
r_id: 9273
rv_id: 1263141
rule_id: L1Uyb8
version_id: ExTExX0
url: https://semgrep.dev/playground/r/ExTExX0/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- focus-metavariable: $SINK
- pattern-either:
- pattern-inside: |
$PATH = require('path');
...
- pattern-inside: |
import $PATH from 'path';
...
- pattern-either:
- pattern: $PATH.join(...,$SINK,...)
- pattern: $PATH.resolve(...,$SINK,...)
- patterns:
- focus-metavariable: $SINK
- pattern-inside: |
import 'path';
...
- pattern-either:
- pattern: path.join(...,$SINK,...)
- pattern: path.resolve(...,$SINK,...)
pattern-sanitizers:
- pattern: $Y.replace(...)
- pattern: $Y.indexOf(...)
- pattern: |
function ... (...) {
...
<... $Y.indexOf(...) ...>
...
}
- patterns:
- pattern: $FUNC(...)
- metavariable-regex:
metavariable: $FUNC
regex: sanitize
- id: javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event
message: Xml Parser is used inside Request Event. Make sure that unverified user
data can not reach the XML Parser, as it can result in XML External or Internal
Entity (XXE) Processing vulnerabilities
metadata:
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
category: security
technology:
- express
references:
- https://www.npmjs.com/package/xml2json
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event
shortlink: https://sg.run/x1AA
semgrep.dev:
rule:
r_id: 9274
rv_id: 1263146
rule_id: 8GUjkk
version_id: QkTGqgo
url: https://semgrep.dev/playground/r/QkTGqgo/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
require('xml2json');
...
- pattern-inside: |
import 'xml2json';
...
- pattern: $REQ.on('...', function(...) { ... $EXPAT.toJson($INPUT,...); ... })
- focus-metavariable: $INPUT
- id: javascript.express.security.audit.res-render-injection.res-render-injection
message: User controllable data `$REQ` enters `$RES.render(...)` this can lead to
the loading of other HTML/templating pages that they may not be authorized to
render. An attacker may attempt to use directory traversal techniques e.g. `../folder/index`
to access other HTML pages on the file system. Where possible, do not allow users
to define what should be loaded in $RES.render or use an allow list for the existing
application.
options:
interfile: true
metadata:
interfile: true
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-706: Use of Incorrectly-Resolved Name or Reference'
category: security
technology:
- express
references:
- http://expressjs.com/en/4x/api.html#res.render
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/javascript.express.security.audit.res-render-injection.res-render-injection
shortlink: https://sg.run/eLjd
semgrep.dev:
rule:
r_id: 9276
rv_id: 1263149
rule_id: QrUzrq
version_id: PkTR3OY
url: https://semgrep.dev/playground/r/PkTR3OY/javascript.express.security.audit.res-render-injection.res-render-injection
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-either:
- pattern: $RES.render($SINK, ...)
- focus-metavariable: $SINK
- id: javascript.express.security.audit.xss.direct-response-write.direct-response-write
message: Detected directly writing to a Response object from user-defined input.
This bypasses any HTML escaping and may expose your application to a Cross-Site-scripting
(XSS) vulnerability. Instead, use 'resp.render()' to render safely escaped HTML.
options:
interfile: true
metadata:
interfile: true
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
category: security
technology:
- express
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
vulnerability_class:
- Cross-Site-Scripting (XSS)
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/javascript.express.security.audit.xss.direct-response-write.direct-response-write
shortlink: https://sg.run/vzGl
semgrep.dev:
rule:
r_id: 9277
rv_id: 1263150
rule_id: 3qUPA1
version_id: JdTzxeg
url: https://semgrep.dev/playground/r/JdTzxeg/javascript.express.security.audit.xss.direct-response-write.direct-response-write
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)
- pattern-not-inside: |
function ... ($REQ, $RES) {
...
$RES.$SET('Content-Type', '$TYPE')
}
- pattern-not-inside: |
$APP.$METHOD(..., function $FUNC($REQ, $RES) {
...
$RES.$SET('Content-Type', '$TYPE')
})
- pattern-not-inside: |
function ... ($REQ, $RES, $NEXT) {
...
$RES.$SET('Content-Type', '$TYPE')
}
- pattern-not-inside: |
function ... ($REQ, $RES) {
...
$RES.set('$TYPE')
}
- pattern-not-inside: |
$APP.$METHOD(..., function $FUNC($REQ, $RES) {
...
$RES.set('$TYPE')
})
- pattern-not-inside: |
function ... ($REQ, $RES, $NEXT) {
...
$RES.set('$TYPE')
}
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- pattern-not-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{
...
$RES.$SET('Content-Type', '$TYPE')
}
- pattern-not-inside: |
({ $REQ }: Request,$RES: Response) => {
...
$RES.$SET('Content-Type', '$TYPE')
}
- pattern-not-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{
...
$RES.set('$TYPE')
}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: body
pattern-sinks:
- patterns:
- pattern-inside: function ... (..., $RES,...) {...}
- pattern-either:
- pattern: $RES.write($ARG)
- pattern: $RES.send($ARG)
- pattern-not: $RES. ... .set('...'). ... .send($ARG)
- pattern-not: $RES. ... .type('...'). ... .send($ARG)
- pattern-not-inside: $RES.$METHOD({ ... })
- focus-metavariable: $ARG
pattern-sanitizers:
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
import * as $S from "underscore.string"
...
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
$S = require("underscore.string")
...
- pattern-either:
- pattern: $S.escapeHTML(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "dompurify"
...
- pattern-inside: |
import { ..., $S,... } from "dompurify"
...
- pattern-inside: |
import * as $S from "dompurify"
...
- pattern-inside: |
$S = require("dompurify")
...
- pattern-inside: |
import $S from "isomorphic-dompurify"
...
- pattern-inside: |
import * as $S from "isomorphic-dompurify"
...
- pattern-inside: |
$S = require("isomorphic-dompurify")
...
- pattern-either:
- patterns:
- pattern-inside: |
$VALUE = $S(...)
...
- pattern: $VALUE.sanitize(...)
- patterns:
- pattern-inside: |
$VALUE = $S.sanitize
...
- pattern: $S(...)
- pattern: $S.sanitize(...)
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'xss';
...
- pattern-inside: |
import * as $S from 'xss';
...
- pattern-inside: |
$S = require("xss")
...
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'sanitize-html';
...
- pattern-inside: |
import * as $S from "sanitize-html";
...
- pattern-inside: |
$S = require("sanitize-html")
...
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
$S = new Remarkable()
...
- pattern: $S.render(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'express-xss-sanitizer';
...
- pattern-inside: |
import * as $S from "express-xss-sanitizer";
...
- pattern-inside: |
const { ..., $S, ... } = require('express-xss-sanitizer');
...
- pattern-inside: |
var { ..., $S, ... } = require('express-xss-sanitizer');
...
- pattern-inside: |
let { ...,$S,... } = require('express-xss-sanitizer');
...
- pattern-inside: |
$S = require("express-xss-sanitizer")
...
- pattern: $S(...)
- patterns:
- pattern: $RES. ... .type('$F'). ... .send(...)
- metavariable-regex:
metavariable: $F
regex: (?!.*text/html)
- patterns:
- pattern-inside: |
$X = [...];
...
- pattern: |
if(<... !$X.includes($SOURCE)...>) {
...
return ...
}
...
- pattern: $SOURCE
- id: javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret
message: A hard-coded credential was detected. It is not recommended to store credentials
in source-code, as this risks secrets being leaked and used by either an internal
or external malicious adversary. It is recommended to use environment variables
to securely provide credentials or retrieve credentials from a secure vault or
HSM (Hardware Security Module).
metadata:
interfile: true
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
asvs:
section: 'V3: Session Management Verification Requirements'
control_id: 3.5.2 Static API keys or secret
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
version: '4'
category: security
technology:
- jose
- jwt
- secrets
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret
shortlink: https://sg.run/Ro1g
semgrep.dev:
rule:
r_id: 9293
rv_id: 1263182
rule_id: JDUyRl
version_id: d6TyxbX
url: https://semgrep.dev/playground/r/d6TyxbX/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret
origin: community
languages:
- javascript
- typescript
severity: WARNING
patterns:
- pattern-inside: |
$JOSE = require("jose");
...
- pattern-either:
- pattern-inside: |
var {JWT} = $JOSE;
...
- pattern-inside: |
var {JWK, JWT} = $JOSE;
...
- pattern-inside: |
const {JWT} = $JOSE;
...
- pattern-inside: |
const {JWK, JWT} = $JOSE;
...
- pattern-inside: |
let {JWT} = $JOSE;
...
- pattern-inside: |
let {JWK, JWT} = $JOSE;
...
- pattern-either:
- pattern: |
JWT.verify($P, "...", ...);
- pattern: |
JWT.sign($P, "...", ...);
- pattern: "JWT.verify($P, JWK.asKey(\"...\"), ...); \n"
- pattern: |
$JWT.sign($P, JWK.asKey("..."), ...);
options:
symbolic_propagation: true
interfile: true
- id: javascript.jose.security.jwt-none-alg.jwt-none-alg
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
assumes the integrity of the token has already been verified. This would allow
a malicious actor to forge a JWT token that will automatically be verified. Do
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
asvs:
section: 'V3: Session Management Verification Requirements'
control_id: 3.5.3 Insecue Stateless Session Tokens
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
version: '4'
category: security
technology:
- jose
- jwt
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/javascript.jose.security.jwt-none-alg.jwt-none-alg
shortlink: https://sg.run/AvRL
semgrep.dev:
rule:
r_id: 9294
rv_id: 1263183
rule_id: 5rUOGN
version_id: ZRTKAyb
url: https://semgrep.dev/playground/r/ZRTKAyb/javascript.jose.security.jwt-none-alg.jwt-none-alg
origin: community
languages:
- javascript
- typescript
severity: ERROR
pattern-either:
- pattern: |
var $JOSE = require("jose");
...
var { JWK, JWT } = $JOSE;
...
var $T = JWT.verify($P, JWK.None,...);
- pattern: |
var $JOSE = require("jose");
...
var { JWK, JWT } = $JOSE;
...
$T = JWT.verify($P, JWK.None,...);
- pattern: |
var $JOSE = require("jose");
...
var { JWK, JWT } = $JOSE;
...
JWT.verify($P, JWK.None,...);
- id: javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret
message: A hard-coded credential was detected. It is not recommended to store credentials
in source-code, as this risks secrets being leaked and used by either an internal
or external malicious adversary. It is recommended to use environment variables
to securely provide credentials or retrieve credentials from a secure vault or
HSM (Hardware Security Module).
metadata:
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
asvs:
section: 'V3: Session Management Verification Requirements'
control_id: 3.5.2 Static API keys or secret
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
version: '4'
category: security
technology:
- jwt
- javascript
- secrets
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret
shortlink: https://sg.run/4xN9
semgrep.dev:
rule:
r_id: 9300
rv_id: 1263189
rule_id: WAUon7
version_id: gETB75D
url: https://semgrep.dev/playground/r/gETB75D/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern: "$X = '...' \n"
- pattern: "$X = '$Y' \n"
- patterns:
- pattern-either:
- pattern-inside: |
$JWT.sign($DATA,"...",...);
- pattern-inside: |
$JWT.verify($DATA,"...",...);
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
$JWT = require("jsonwebtoken")
...
- pattern-inside: |
import $JWT from "jsonwebtoken"
...
- pattern-inside: |
import * as $JWT from "jsonwebtoken"
...
- pattern-inside: |
import {...,$JWT,...} from "jsonwebtoken"
...
- pattern-either:
- pattern-inside: |
$JWT.sign($DATA,$VALUE,...);
- pattern-inside: |
$JWT.verify($DATA,$VALUE,...);
- focus-metavariable: $VALUE
- id: javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
assumes the integrity of the token has already been verified. This would allow
a malicious actor to forge a JWT token that will automatically be verified. Do
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
asvs:
section: 'V3: Session Management Verification Requirements'
control_id: 3.5.3 Insecue Stateless Session Tokens
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
version: '4'
category: security
technology:
- jwt
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg
shortlink: https://sg.run/PJXv
semgrep.dev:
rule:
r_id: 9301
rv_id: 1263190
rule_id: 0oU53g
version_id: QkTGqQo
url: https://semgrep.dev/playground/r/QkTGqQo/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg
origin: community
languages:
- javascript
- typescript
severity: ERROR
patterns:
- pattern-inside: |
$JWT = require("jsonwebtoken");
...
- pattern: $JWT.verify($P, $X, {algorithms:[...,'none',...]},...)
- id: javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression
message: Detected use of dynamic execution of JavaScript which may come from user-input,
which can lead to Cross-Site-Scripting (XSS). Where possible avoid including user-input
in functions which dynamically execute user-input.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-eval-with-expression.js
references:
- https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval#never_use_eval!
category: security
technology:
- javascript
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression
shortlink: https://sg.run/6nwK
semgrep.dev:
rule:
r_id: 9315
rv_id: 1263214
rule_id: yyUngo
version_id: WrTqKkJ
url: https://semgrep.dev/playground/r/WrTqKkJ/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
$PROP = new URLSearchParams($WINDOW. ... .location.search).get('...')
...
- pattern-inside: |
$PROP = new URLSearchParams(location.search).get('...')
...
- pattern-inside: |
$PROP = new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...')
...
- pattern-inside: |
$PROP = new URLSearchParams(location.hash.substring(1)).get('...')
...
- focus-metavariable: $PROP
- patterns:
- pattern-either:
- pattern-inside: |
$PROPS = new URLSearchParams($WINDOW. ... .location.search)
...
- pattern-inside: |
$PROPS = new URLSearchParams(location.search)
...
- pattern-inside: |
$PROPS = new
URLSearchParams($WINDOW. ... .location.hash.substring(1))
...
- pattern-inside: |
$PROPS = new URLSearchParams(location.hash.substring(1))
...
- pattern: $PROPS.get('...')
- focus-metavariable: $PROPS
- patterns:
- pattern-either:
- pattern: location.href
- pattern: location.hash
- pattern: location.search
- pattern: $WINDOW. ... .location.href
- pattern: $WINDOW. ... .location.hash
- pattern: $WINDOW. ... .location.search
pattern-sinks:
- patterns:
- pattern-either:
- pattern: eval(<... $SINK ...>)
- pattern: window.eval(<... $SINK ...>)
- pattern: new Function(<... $SINK ...>)
- pattern: new Function(<... $SINK ...>)(...)
- pattern: setTimeout(<... $SINK ...>,...)
- pattern: setInterval(<... $SINK ...>,...)
- focus-metavariable: $SINK
pattern-sanitizers:
- patterns:
- pattern-either:
- pattern: location.href = $FUNC(...)
- pattern: location.hash = $FUNC(...)
- pattern: location.search = $FUNC(...)
- pattern: $WINDOW. ... .location.href = $FUNC(...)
- pattern: $WINDOW. ... .location.hash = $FUNC(...)
- pattern: $WINDOW. ... .location.search = $FUNC(...)
- id: javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret
message: A hard-coded credential was detected. It is not recommended to store credentials
in source-code, as this risks secrets being leaked and used by either an internal
or external malicious adversary. It is recommended to use environment variables
to securely provide credentials or retrieve credentials from a secure vault or
HSM (Hardware Security Module).
metadata:
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
asvs:
section: 'V3: Session Management Verification Requirements'
control_id: 3.5.2 Static API keys or secret
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management
version: '4'
category: security
technology:
- jwt
- nodejs
- secrets
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret
shortlink: https://sg.run/vz70
semgrep.dev:
rule:
r_id: 9333
rv_id: 1263225
rule_id: QrUzq6
version_id: X0TzyoE
url: https://semgrep.dev/playground/r/X0TzyoE/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- by-side-effect: true
patterns:
- pattern-either:
- pattern: |
{..., clientSecret: "...", ...}
- pattern: |
{..., secretOrKey: "...", ...}
- pattern: |
{..., consumerSecret: "...", ...}
- patterns:
- pattern-inside: |
$OBJ = {}
...
- pattern-either:
- pattern: |
$OBJ.clientSecret = "..."
- pattern: |
$OBJ.secretOrKey = "..."
- pattern: |
$OBJ.consumerSecret = "..."
- pattern: $OBJ
- patterns:
- pattern-inside: |
$SECRET = '...'
...
- pattern-either:
- pattern: |
{..., clientSecret: $SECRET, ...}
- pattern: |
{..., secretOrKey: $SECRET, ...}
- pattern: |
{..., consumerSecret: $SECRET, ...}
- patterns:
- pattern-inside: |
$SECRET = '...'
...
- pattern-either:
- pattern-inside: |
$VALUE = {..., clientSecret: $SECRET, ...}
...
- pattern-inside: |
$VALUE = {..., secretOrKey: $SECRET, ...}
...
- pattern-inside: |
$VALUE = {..., consumerSecret: $SECRET, ...}
...
- pattern: $VALUE
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
$F = require("$I").Strategy
...
- pattern-inside: |
$F = require("$I")
...
- pattern-inside: |
import { $STRAT as $F } from '$I'
...
- pattern-inside: |
import $F from '$I'
...
- metavariable-regex:
metavariable: $I
regex: (passport-.*)
- pattern-inside: |
new $F($VALUE,...)
- focus-metavariable: $VALUE
- id: json.aws.security.public-s3-policy-statement.public-s3-policy-statement
pattern: |
{
"Effect": "Allow",
"Principal": "*",
"Resource": [
..., "=~/arn:aws:s3.*/", ...
],
...
}
message: Detected public S3 bucket policy. This policy allows anyone to access certain
properties of or items in the bucket. Do not do this unless you will never have
sensitive data inside the bucket.
metadata:
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls'
references:
- https://docs.aws.amazon.com/AmazonS3/latest/dev/WebsiteAccessPermissionsReqd.html
category: security
technology:
- aws
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/json.aws.security.public-s3-policy-statement.public-s3-policy-statement
shortlink: https://sg.run/Yv1d
semgrep.dev:
rule:
r_id: 9358
rv_id: 1263255
rule_id: 9AU1br
version_id: A8Tgdxq
url: https://semgrep.dev/playground/r/A8Tgdxq/json.aws.security.public-s3-policy-statement.public-s3-policy-statement
origin: community
severity: WARNING
languages:
- json
- id: php.lang.security.assert-use.assert-use
mode: taint
pattern-sources:
- pattern-either:
- patterns:
- pattern-either:
- pattern: $_GET
- pattern: $_POST
- pattern: $_COOKIE
- pattern: $_REQUEST
- pattern: $_SERVER
- patterns:
- pattern: |
Route::$METHOD($ROUTENAME, function(..., $ARG, ...) { ... })
- focus-metavariable: $ARG
pattern-sinks:
- patterns:
- pattern: assert($SINK, ...);
- pattern-not: assert("...", ...);
- pattern: $SINK
message: Calling assert with user input is equivalent to eval'ing.
metadata:
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
references:
- https://www.php.net/manual/en/function.assert
- https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/AssertsSniff.php
category: security
technology:
- php
confidence: HIGH
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/php.lang.security.assert-use.assert-use
shortlink: https://sg.run/3xXW
semgrep.dev:
rule:
r_id: 9387
rv_id: 1263272
rule_id: DbUpjk
version_id: 9lT4bLx
url: https://semgrep.dev/playground/r/9lT4bLx/php.lang.security.assert-use.assert-use
origin: community
languages:
- php
severity: ERROR
- id: php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off
patterns:
- pattern-either:
- pattern: |
$ARG = $IS_VERIFIED;
...
curl_setopt(..., CURLOPT_SSL_VERIFYPEER, $ARG);
- pattern: curl_setopt(..., CURLOPT_SSL_VERIFYPEER, $IS_VERIFIED)
- metavariable-regex:
metavariable: $IS_VERIFIED
regex: 0|false|null
message: SSL verification is disabled but should not be (currently CURLOPT_SSL_VERIFYPEER=
$IS_VERIFIED)
metadata:
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
references:
- https://www.saotn.org/dont-turn-off-curlopt_ssl_verifypeer-fix-php-configuration/
category: security
technology:
- php
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off
shortlink: https://sg.run/PJqv
semgrep.dev:
rule:
r_id: 9389
rv_id: 1263277
rule_id: 0oU5Xg
version_id: kbTzG9b
url: https://semgrep.dev/playground/r/kbTzG9b/php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off
origin: community
languages:
- php
severity: ERROR
- id: php.lang.security.phpinfo-use.phpinfo-use
pattern: phpinfo(...);
message: The 'phpinfo' function may reveal sensitive information about your environment.
metadata:
cwe:
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
references:
- https://www.php.net/manual/en/function.phpinfo
- https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/PhpinfosSniff.php
category: security
technology:
- php
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/php.lang.security.phpinfo-use.phpinfo-use
shortlink: https://sg.run/W82E
semgrep.dev:
rule:
r_id: 9397
rv_id: 1263298
rule_id: ReUglY
version_id: RGT0LN0
url: https://semgrep.dev/playground/r/RGT0LN0/php.lang.security.phpinfo-use.phpinfo-use
origin: community
languages:
- php
severity: ERROR
- id: python.boto3.security.hardcoded-token.hardcoded-token
message: A hard-coded credential was detected. It is not recommended to store credentials
in source-code, as this risks secrets being leaked and used by either an internal
or external malicious adversary. It is recommended to use environment variables
to securely provide credentials or retrieve credentials from a secure vault or
HSM (Hardware Security Module).
metadata:
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
- https://bento.dev/checks/boto3/hardcoded-access-token/
- https://aws.amazon.com/blogs/security/what-to-do-if-you-inadvertently-expose-an-aws-access-key/
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
category: security
technology:
- boto3
- secrets
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/python.boto3.security.hardcoded-token.hardcoded-token
shortlink: https://sg.run/LwQ6
semgrep.dev:
rule:
r_id: 9439
rv_id: 1263347
rule_id: 5rUOwK
version_id: gETB78n
url: https://semgrep.dev/playground/r/gETB78n/python.boto3.security.hardcoded-token.hardcoded-token
origin: community
languages:
- python
severity: WARNING
mode: taint
pattern-sources:
- pattern: |
"..."
pattern-sinks:
- patterns:
- pattern-either:
- pattern: $W(...,$TOKEN="$VALUE",...)
- pattern: $BOTO. ... .$W(...,$TOKEN="$VALUE",...)
- metavariable-regex:
metavariable: $TOKEN
regex: (aws_session_token|aws_access_key_id|aws_secret_access_key)
- metavariable-pattern:
language: generic
metavariable: $VALUE
patterns:
- pattern-either:
- pattern-regex: ^AKI
- pattern-regex: ^[A-Za-z0-9/+=]+$
- metavariable-analysis:
metavariable: $VALUE
analyzer: entropy
- id: python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea
message: IDEA (International Data Encryption Algorithm) is a block cipher created
in 1991. It is an optional component of the OpenPGP standard. This cipher is
susceptible to attacks when using weak keys. It is recommended that you do not
use this cipher for new applications. Use a strong symmetric cipher such as EAS
instead. With the `cryptography` package it is recommended to use `Fernet` which
is a secure implementation of AES in CBC mode with a 128-bit key. Alternatively,
keep using the `Cipher` class from the hazmat primitives but use the AES algorithm
instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B304
references:
- https://tools.ietf.org/html/rfc5469
- https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#cryptography.hazmat.primitives.ciphers.algorithms.IDEA
category: security
technology:
- cryptography
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
functional-categories:
- crypto::search::symmetric-algorithm::cryptography
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea
shortlink: https://sg.run/3xyK
semgrep.dev:
rule:
r_id: 9443
rv_id: 1263350
rule_id: BYUNPg
version_id: 44TEjNJ
url: https://semgrep.dev/playground/r/44TEjNJ/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea
origin: community
severity: WARNING
languages:
- python
patterns:
- pattern: cryptography.hazmat.primitives.ciphers.algorithms.$IDEA($KEY)
- metavariable-regex:
metavariable: $IDEA
regex: ^(IDEA)$
- focus-metavariable: $IDEA
fix: AES
- id: python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb
message: ECB (Electronic Code Book) is the simplest mode of operation for block
ciphers. Each block of data is encrypted in the same way. This means identical
plaintext blocks will always result in identical ciphertext blocks, which can
leave significant patterns in the output. Use a different, cryptographically strong
mode instead, such as GCM.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L101
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B305
references:
- https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#insecure-modes
- https://crypto.stackexchange.com/questions/20941/why-shouldnt-i-use-ecb-encryption
category: security
technology:
- cryptography
subcategory:
- audit
likelihood: LOW
impact: LOW
confidence: MEDIUM
functional-categories:
- crypto::search::mode::cryptography
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb
shortlink: https://sg.run/4xr5
semgrep.dev:
rule:
r_id: 9444
rv_id: 1263351
rule_id: DbUp5g
version_id: PkTR3w7
url: https://semgrep.dev/playground/r/PkTR3w7/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb
origin: community
severity: WARNING
languages:
- python
pattern: cryptography.hazmat.primitives.ciphers.modes.ECB($IV)
fix: cryptography.hazmat.primitives.ciphers.modes.GCM($IV)
- id: python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
patterns:
- pattern: cryptography.hazmat.primitives.hashes.$SHA(...)
- metavariable-pattern:
metavariable: $SHA
pattern: |
SHA1
- focus-metavariable: $SHA
fix: |
SHA256
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
collision resistant and is therefore not suitable as a cryptographic signature.
Use SHA256 or SHA3 instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B303
references:
- https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#sha-1
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
- http://2012.sharcs.org/slides/stevens.pdf
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
category: security
technology:
- cryptography
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
functional-categories:
- crypto::search::symmetric-algorithm::cryptography
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
shortlink: https://sg.run/J9Qy
semgrep.dev:
rule:
r_id: 9446
rv_id: 1263353
rule_id: 0oU5dN
version_id: 5PTo1l0
url: https://semgrep.dev/playground/r/5PTo1l0/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
origin: community
severity: WARNING
languages:
- python
- id: python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size
patterns:
- pattern-either:
- pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key(...,
key_size=$SIZE, ...)
- pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key($SIZE,
...)
- metavariable-comparison:
metavariable: $SIZE
comparison: $SIZE < 2048
- focus-metavariable: $SIZE
fix: |
2048
message: Detected an insufficient key size for DSA. NIST recommends a key size of
2048 or higher.
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
references:
- https://www.cosic.esat.kuleuven.be/ecrypt/ecrypt2/documents/D.SPA.20.pdf
- https://cryptography.io/en/latest/hazmat/primitives/asymmetric/dsa/
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf
category: security
technology:
- cryptography
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
functional-categories:
- crypto::search::key-length::cryptography
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size
shortlink: https://sg.run/5Qb0
semgrep.dev:
rule:
r_id: 9447
rv_id: 1263354
rule_id: KxUb0x
version_id: GxTkeOK
url: https://semgrep.dev/playground/r/GxTkeOK/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size
origin: community
languages:
- python
severity: WARNING
- id: python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size
patterns:
- pattern-inside: cryptography.hazmat.primitives.asymmetric.ec.generate_private_key(...)
- pattern: cryptography.hazmat.primitives.asymmetric.ec.$SIZE
- metavariable-pattern:
metavariable: $SIZE
pattern-either:
- pattern: SECP192R1
- pattern: SECT163K1
- pattern: SECT163R2
- focus-metavariable: $SIZE
fix: |
SECP256R1
message: Detected an insufficient curve size for EC. NIST recommends a key size
of 224 or higher. For example, use 'ec.SECP256R1'.
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
references:
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf
- https://cryptography.io/en/latest/hazmat/primitives/asymmetric/ec/#elliptic-curves
category: security
technology:
- cryptography
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
functional-categories:
- crypto::search::key-length::cryptography
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size
shortlink: https://sg.run/GeQq
semgrep.dev:
rule:
r_id: 9448
rv_id: 1263355
rule_id: qNUjZ3
version_id: RGT0LW6
url: https://semgrep.dev/playground/r/RGT0LW6/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size
origin: community
languages:
- python
severity: WARNING
- id: python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size
patterns:
- pattern-either:
- pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key(...,
key_size=$SIZE, ...)
- pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key($EXP,
$SIZE, ...)
- metavariable-comparison:
metavariable: $SIZE
comparison: $SIZE < 2048
- focus-metavariable: $SIZE
fix: |
2048
message: Detected an insufficient key size for RSA. NIST recommends a key size of
2048 or higher.
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
references:
- https://cryptography.io/en/latest/hazmat/primitives/asymmetric/rsa/
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf
category: security
technology:
- cryptography
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
functional-categories:
- crypto::search::key-length::cryptography
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size
shortlink: https://sg.run/RoQq
semgrep.dev:
rule:
r_id: 9449
rv_id: 1263356
rule_id: lBU9jn
version_id: A8TgdPK
url: https://semgrep.dev/playground/r/A8TgdPK/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size
origin: community
languages:
- python
severity: WARNING
- id: python.distributed.security.require-encryption
patterns:
- pattern: |
distributed.security.Security(..., require_encryption=$VAL, ...)
- metavariable-pattern:
metavariable: $VAL
pattern: |
False
- focus-metavariable: $VAL
fix: |
True
message: Initializing a security context for Dask (`distributed`) without "require_encryption"
keyword argument may silently fail to provide security.
severity: WARNING
metadata:
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://distributed.dask.org/en/latest/tls.html?highlight=require_encryption#parameters
category: security
technology:
- distributed
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/python.distributed.security.require-encryption
shortlink: https://sg.run/AvQ2
semgrep.dev:
rule:
r_id: 9450
rv_id: 1263358
rule_id: YGURy0
version_id: DkTRbol
url: https://semgrep.dev/playground/r/DkTRbol/python.distributed.security.require-encryption
origin: community
languages:
- python
- id: python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization
metadata:
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
references:
- https://docs.python.org/3/library/pickle.html
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization
shortlink: https://sg.run/9oyr
semgrep.dev:
rule:
r_id: 9467
rv_id: 1409400
rule_id: OrU3e6
version_id: GxTlb9e
url: https://semgrep.dev/playground/r/GxTlb9e/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization
origin: community
message: Avoid using insecure deserialization library, backed by `pickle`, `_pickle`,
`cpickle`, `dill`, `shelve`, or `yaml`, which are known to lead to remote code
execution vulnerabilities.
languages:
- python
severity: ERROR
mode: taint
pattern-sources:
- pattern-either:
- patterns:
- pattern-inside: |
def $INSIDE(..., $PARAM, ...):
...
- pattern-either:
- pattern: request.$REQFUNC(...)
- pattern: request.$REQFUNC.get(...)
- pattern: request.$REQFUNC[...]
pattern-sinks:
- pattern-either:
- patterns:
- pattern-either:
- pattern: |
pickle.$PICKLEFUNC(...)
- pattern: |
_pickle.$PICKLEFUNC(...)
- pattern: |
cPickle.$PICKLEFUNC(...)
- pattern: |
shelve.$PICKLEFUNC(...)
- metavariable-regex:
metavariable: $PICKLEFUNC
regex: dumps|dump|load|loads
- patterns:
- pattern: dill.$DILLFUNC(...)
- metavariable-regex:
metavariable: $DILLFUNC
regex: dump|dump_session|dumps|load|load_session|loads
- patterns:
- pattern: yaml.$YAMLFUNC(...)
- pattern-not: yaml.$YAMLFUNC(..., Dumper=SafeDumper, ...)
- pattern-not: yaml.$YAMLFUNC(..., Dumper=yaml.SafeDumper, ...)
- pattern-not: yaml.$YAMLFUNC(..., Loader=SafeLoader, ...)
- pattern-not: yaml.$YAMLFUNC(..., Loader=yaml.SafeLoader, ...)
- metavariable-regex:
metavariable: $YAMLFUNC
regex: dump|dump_all|load|load_all
- id: python.django.security.injection.open-redirect.open-redirect
message: Data from request ($DATA) is passed to redirect(). This is an open redirect
and could be exploited. Ensure you are redirecting to safe URLs by using django.utils.http.is_safe_url().
See https://cwe.mitre.org/data/definitions/601.html for more information.
metadata:
cwe:
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://www.djm.org.uk/posts/djangos-little-protections-word-redirect-dangers/
- https://github.com/django/django/blob/d1b7bd030b1db111e1a3505b1fc029ab964382cc/django/utils/http.py#L231
category: security
technology:
- django
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Open Redirect
source: https://semgrep.dev/r/python.django.security.injection.open-redirect.open-redirect
shortlink: https://sg.run/Ave2
semgrep.dev:
rule:
r_id: 9494
rv_id: 1263393
rule_id: PeUZgr
version_id: 3ZT4XD7
url: https://semgrep.dev/playground/r/3ZT4XD7/python.django.security.injection.open-redirect.open-redirect
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-not-inside: |
def $FUNC(...):
...
django.utils.http.is_safe_url(...)
...
- pattern-not-inside: |
def $FUNC(...):
...
if <... django.utils.http.is_safe_url(...) ...>:
...
- pattern-not-inside: |
def $FUNC(...):
...
django.utils.http.url_has_allowed_host_and_scheme(...)
...
- pattern-not-inside: |
def $FUNC(...):
...
if <... django.utils.http.url_has_allowed_host_and_scheme(...) ...>:
...
- pattern-either:
- pattern: django.shortcuts.redirect(..., request.$W.get(...), ...)
- pattern: django.shortcuts.redirect(..., $S.format(..., request.$W.get(...),
...), ...)
- pattern: django.shortcuts.redirect(..., $S % request.$W.get(...), ...)
- pattern: django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.shortcuts.redirect(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.shortcuts.redirect(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.shortcuts.redirect(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.shortcuts.redirect(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: $A = django.shortcuts.redirect(..., request.$W.get(...), ...)
- pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W.get(...),
...), ...)
- pattern: $A = django.shortcuts.redirect(..., $S % request.$W.get(...), ...)
- pattern: $A = django.shortcuts.redirect(..., f"...{request.$W.get(...)}...",
...)
- pattern: return django.shortcuts.redirect(..., request.$W.get(...), ...)
- pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W.get(...),
...), ...)
- pattern: return django.shortcuts.redirect(..., $S % request.$W.get(...), ...)
- pattern: return django.shortcuts.redirect(..., f"...{request.$W.get(...)}...",
...)
- pattern: django.shortcuts.redirect(..., request.$W(...), ...)
- pattern: django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...),
...)
- pattern: django.shortcuts.redirect(..., $S % request.$W(...), ...)
- pattern: django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...)
- pattern: |
$DATA = request.$W(...)
...
django.shortcuts.redirect(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.shortcuts.redirect(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.shortcuts.redirect(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.shortcuts.redirect(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: $A = django.shortcuts.redirect(..., request.$W(...), ...)
- pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W(...),
...), ...)
- pattern: $A = django.shortcuts.redirect(..., $S % request.$W(...), ...)
- pattern: $A = django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...)
- pattern: return django.shortcuts.redirect(..., request.$W(...), ...)
- pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W(...),
...), ...)
- pattern: return django.shortcuts.redirect(..., $S % request.$W(...), ...)
- pattern: return django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...)
- pattern: django.shortcuts.redirect(..., request.$W[...], ...)
- pattern: django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...),
...)
- pattern: django.shortcuts.redirect(..., $S % request.$W[...], ...)
- pattern: django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...)
- pattern: |
$DATA = request.$W[...]
...
django.shortcuts.redirect(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.shortcuts.redirect(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.shortcuts.redirect(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.shortcuts.redirect(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: $A = django.shortcuts.redirect(..., request.$W[...], ...)
- pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W[...],
...), ...)
- pattern: $A = django.shortcuts.redirect(..., $S % request.$W[...], ...)
- pattern: $A = django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...)
- pattern: return django.shortcuts.redirect(..., request.$W[...], ...)
- pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W[...],
...), ...)
- pattern: return django.shortcuts.redirect(..., $S % request.$W[...], ...)
- pattern: return django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...)
- pattern: django.shortcuts.redirect(..., request.$W, ...)
- pattern: django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...)
- pattern: django.shortcuts.redirect(..., $S % request.$W, ...)
- pattern: django.shortcuts.redirect(..., f"...{request.$W}...", ...)
- pattern: |
$DATA = request.$W
...
django.shortcuts.redirect(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.shortcuts.redirect(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.shortcuts.redirect(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.shortcuts.redirect(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
django.shortcuts.redirect(..., $INTERM, ...)
- pattern: $A = django.shortcuts.redirect(..., request.$W, ...)
- pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W, ...),
...)
- pattern: $A = django.shortcuts.redirect(..., $S % request.$W, ...)
- pattern: $A = django.shortcuts.redirect(..., f"...{request.$W}...", ...)
- pattern: return django.shortcuts.redirect(..., request.$W, ...)
- pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W, ...),
...)
- pattern: return django.shortcuts.redirect(..., $S % request.$W, ...)
- pattern: return django.shortcuts.redirect(..., f"...{request.$W}...", ...)
- pattern: django.http.HttpResponseRedirect(..., request.$W.get(...), ...)
- pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...),
...), ...)
- pattern: django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...)
- pattern: django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...",
...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponseRedirect(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponseRedirect(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponseRedirect(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: $A = django.http.HttpResponseRedirect(..., request.$W.get(...), ...)
- pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...),
...), ...)
- pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W.get(...),
...)
- pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...",
...)
- pattern: return django.http.HttpResponseRedirect(..., request.$W.get(...), ...)
- pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...),
...), ...)
- pattern: return django.http.HttpResponseRedirect(..., $S % request.$W.get(...),
...)
- pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...",
...)
- pattern: django.http.HttpResponseRedirect(..., request.$W(...), ...)
- pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...),
...), ...)
- pattern: django.http.HttpResponseRedirect(..., $S % request.$W(...), ...)
- pattern: django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponseRedirect(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponseRedirect(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponseRedirect(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: $A = django.http.HttpResponseRedirect(..., request.$W(...), ...)
- pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...),
...), ...)
- pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W(...), ...)
- pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...",
...)
- pattern: return django.http.HttpResponseRedirect(..., request.$W(...), ...)
- pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...),
...), ...)
- pattern: return django.http.HttpResponseRedirect(..., $S % request.$W(...),
...)
- pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...",
...)
- pattern: django.http.HttpResponseRedirect(..., request.$W[...], ...)
- pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...],
...), ...)
- pattern: django.http.HttpResponseRedirect(..., $S % request.$W[...], ...)
- pattern: django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponseRedirect(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponseRedirect(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponseRedirect(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: $A = django.http.HttpResponseRedirect(..., request.$W[...], ...)
- pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...],
...), ...)
- pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W[...], ...)
- pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...",
...)
- pattern: return django.http.HttpResponseRedirect(..., request.$W[...], ...)
- pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...],
...), ...)
- pattern: return django.http.HttpResponseRedirect(..., $S % request.$W[...],
...)
- pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...",
...)
- pattern: django.http.HttpResponseRedirect(..., request.$W, ...)
- pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...),
...)
- pattern: django.http.HttpResponseRedirect(..., $S % request.$W, ...)
- pattern: django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponseRedirect(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponseRedirect(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponseRedirect(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
django.http.HttpResponseRedirect(..., $INTERM, ...)
- pattern: $A = django.http.HttpResponseRedirect(..., request.$W, ...)
- pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W,
...), ...)
- pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W, ...)
- pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...)
- pattern: return django.http.HttpResponseRedirect(..., request.$W, ...)
- pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W,
...), ...)
- pattern: return django.http.HttpResponseRedirect(..., $S % request.$W, ...)
- pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W}...",
...)
- metavariable-regex:
metavariable: $W
regex: (?!get_full_path)
- id: python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse
message: Found user-controlled request data passed into HttpResponse. This could
be vulnerable to XSS, leading to attackers gaining access to user cookies and
protected information. Ensure that the request data is properly escaped or sanitzed.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse
shortlink: https://sg.run/BkvA
semgrep.dev:
rule:
r_id: 9495
rv_id: 1263398
rule_id: JDUydR
version_id: GxTke5K
url: https://semgrep.dev/playground/r/GxTke5K/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: django.http.HttpResponse(..., $S.format(..., request.$W.get(...), ...),
...)
- pattern: django.http.HttpResponse(..., $S % request.$W.get(...), ...)
- pattern: django.http.HttpResponse(..., f"...{request.$W.get(...)}...", ...)
- pattern: django.http.HttpResponse(..., request.$W.get(...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponse(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponse(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponse(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponse(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: $A = django.http.HttpResponse(..., request.$W.get(...), ...)
- pattern: return django.http.HttpResponse(..., request.$W.get(...), ...)
- pattern: django.http.HttpResponse(..., $S.format(..., request.$W(...), ...),
...)
- pattern: django.http.HttpResponse(..., $S % request.$W(...), ...)
- pattern: django.http.HttpResponse(..., f"...{request.$W(...)}...", ...)
- pattern: django.http.HttpResponse(..., request.$W(...), ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponse(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponse(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponse(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponse(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: $A = django.http.HttpResponse(..., request.$W(...), ...)
- pattern: return django.http.HttpResponse(..., request.$W(...), ...)
- pattern: django.http.HttpResponse(..., $S.format(..., request.$W[...], ...),
...)
- pattern: django.http.HttpResponse(..., $S % request.$W[...], ...)
- pattern: django.http.HttpResponse(..., f"...{request.$W[...]}...", ...)
- pattern: django.http.HttpResponse(..., request.$W[...], ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponse(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponse(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponse(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponse(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: $A = django.http.HttpResponse(..., request.$W[...], ...)
- pattern: return django.http.HttpResponse(..., request.$W[...], ...)
- pattern: django.http.HttpResponse(..., $S.format(..., request.$W, ...), ...)
- pattern: django.http.HttpResponse(..., $S % request.$W, ...)
- pattern: django.http.HttpResponse(..., f"...{request.$W}...", ...)
- pattern: django.http.HttpResponse(..., request.$W, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponse(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponse(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponse(..., f"...{$DATA}...", ...)
- pattern: $A = django.http.HttpResponse(..., request.$W, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
$A = django.http.HttpResponse(..., $INTERM, ...)
- pattern: return django.http.HttpResponse(..., request.$W, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponse(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponse(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
django.http.HttpResponse(..., $INTERM, ...)
- id: python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest
message: Found user-controlled request data passed into a HttpResponseBadRequest.
This could be vulnerable to XSS, leading to attackers gaining access to user cookies
and protected information. Ensure that the request data is properly escaped or
sanitzed.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest
shortlink: https://sg.run/DoZP
semgrep.dev:
rule:
r_id: 9496
rv_id: 1263399
rule_id: 5rUOX1
version_id: RGT0LY6
url: https://semgrep.dev/playground/r/RGT0LY6/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W.get(...),
...), ...)
- pattern: django.http.HttpResponseBadRequest(..., $S % request.$W.get(...), ...)
- pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W.get(...)}...",
...)
- pattern: django.http.HttpResponseBadRequest(..., request.$W.get(...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponseBadRequest(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponseBadRequest(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.HttpResponseBadRequest(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: $A = django.http.HttpResponseBadRequest(..., request.$W.get(...), ...)
- pattern: return django.http.HttpResponseBadRequest(..., request.$W.get(...),
...)
- pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W(...),
...), ...)
- pattern: django.http.HttpResponseBadRequest(..., $S % request.$W(...), ...)
- pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W(...)}...",
...)
- pattern: django.http.HttpResponseBadRequest(..., request.$W(...), ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponseBadRequest(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponseBadRequest(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.HttpResponseBadRequest(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: $A = django.http.HttpResponseBadRequest(..., request.$W(...), ...)
- pattern: return django.http.HttpResponseBadRequest(..., request.$W(...), ...)
- pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W[...],
...), ...)
- pattern: django.http.HttpResponseBadRequest(..., $S % request.$W[...], ...)
- pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W[...]}...",
...)
- pattern: django.http.HttpResponseBadRequest(..., request.$W[...], ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponseBadRequest(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponseBadRequest(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.HttpResponseBadRequest(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: $A = django.http.HttpResponseBadRequest(..., request.$W[...], ...)
- pattern: return django.http.HttpResponseBadRequest(..., request.$W[...], ...)
- pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W,
...), ...)
- pattern: django.http.HttpResponseBadRequest(..., $S % request.$W, ...)
- pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W}...", ...)
- pattern: django.http.HttpResponseBadRequest(..., request.$W, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponseBadRequest(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponseBadRequest(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.http.HttpResponseBadRequest(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
django.http.HttpResponseBadRequest(..., $INTERM, ...)
- pattern: $A = django.http.HttpResponseBadRequest(..., request.$W, ...)
- pattern: return django.http.HttpResponseBadRequest(..., request.$W, ...)
- id: python.django.security.injection.request-data-fileresponse.request-data-fileresponse
message: Found user-controlled request data being passed into a file open, which
is them passed as an argument into the FileResponse. This is dangerous because
an attacker could specify an arbitrary file to read, which could result in leaking
important data. Be sure to validate or sanitize the user-inputted filename in
the request data before using it in FileResponse.
metadata:
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/python.django.security.injection.request-data-fileresponse.request-data-fileresponse
shortlink: https://sg.run/W862
semgrep.dev:
rule:
r_id: 9497
rv_id: 1263400
rule_id: GdU7QR
version_id: A8Tgd1K
url: https://semgrep.dev/playground/r/A8Tgd1K/python.django.security.injection.request-data-fileresponse.request-data-fileresponse
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: django.http.FileResponse(..., request.$W.get(...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.http.FileResponse(..., open($DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = open($DATA, ...)
...
django.http.FileResponse(..., $INTERM, ...)
- pattern: $A = django.http.FileResponse(..., request.$W.get(...), ...)
- pattern: return django.http.FileResponse(..., request.$W.get(...), ...)
- pattern: django.http.FileResponse(..., request.$W(...), ...)
- pattern: |
$DATA = request.$W(...)
...
django.http.FileResponse(..., open($DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = open($DATA, ...)
...
django.http.FileResponse(..., $INTERM, ...)
- pattern: $A = django.http.FileResponse(..., request.$W(...), ...)
- pattern: return django.http.FileResponse(..., request.$W(...), ...)
- pattern: django.http.FileResponse(..., request.$W[...], ...)
- pattern: |
$DATA = request.$W[...]
...
django.http.FileResponse(..., open($DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = open($DATA, ...)
...
django.http.FileResponse(..., $INTERM, ...)
- pattern: $A = django.http.FileResponse(..., request.$W[...], ...)
- pattern: return django.http.FileResponse(..., request.$W[...], ...)
- pattern: django.http.FileResponse(..., request.$W, ...)
- pattern: |
$DATA = request.$W
...
django.http.FileResponse(..., open($DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = open($DATA, ...)
...
django.http.FileResponse(..., $INTERM, ...)
- pattern: $A = django.http.FileResponse(..., request.$W, ...)
- pattern: return django.http.FileResponse(..., request.$W, ...)
- id: python.django.security.injection.request-data-write.request-data-write
message: Found user-controlled request data passed into '.write(...)'. This could
be dangerous if a malicious actor is able to control data into sensitive files.
For example, a malicious actor could force rolling of critical log files, or cause
a denial-of-service by using up available disk space. Instead, ensure that request
data is properly escaped or sanitized.
metadata:
cwe:
- 'CWE-93: Improper Neutralization of CRLF Sequences (''CRLF Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- django
references:
- https://owasp.org/Top10/A03_2021-Injection
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/python.django.security.injection.request-data-write.request-data-write
shortlink: https://sg.run/0Q6j
semgrep.dev:
rule:
r_id: 9498
rv_id: 1263401
rule_id: ReUg5z
version_id: BjTkZO5
url: https://semgrep.dev/playground/r/BjTkZO5/python.django.security.injection.request-data-write.request-data-write
origin: community
languages:
- python
severity: WARNING
pattern-either:
- pattern: $F.write(..., request.$W.get(...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$F.write(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$F.write(..., $B.$C(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $B.$C(..., $DATA, ...)
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$F.write(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$F.write(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
$F.write(..., $INTERM, ...)
- pattern: $A = $F.write(..., request.$W.get(...), ...)
- pattern: return $F.write(..., request.$W.get(...), ...)
- pattern: $F.write(..., request.$W(...), ...)
- pattern: |
$DATA = request.$W(...)
...
$F.write(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$F.write(..., $B.$C(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $B.$C(..., $DATA, ...)
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$F.write(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$F.write(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
$F.write(..., $INTERM, ...)
- pattern: $A = $F.write(..., request.$W(...), ...)
- pattern: return $F.write(..., request.$W(...), ...)
- pattern: $F.write(..., request.$W[...], ...)
- pattern: |
$DATA = request.$W[...]
...
$F.write(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$F.write(..., $B.$C(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $B.$C(..., $DATA, ...)
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$F.write(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$F.write(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
$F.write(..., $INTERM, ...)
- pattern: $A = $F.write(..., request.$W[...], ...)
- pattern: return $F.write(..., request.$W[...], ...)
- pattern: $F.write(..., request.$W, ...)
- pattern: |
$DATA = request.$W
...
$F.write(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$F.write(..., $B.$C(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $B.$C(..., $DATA, ...)
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$F.write(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
$F.write(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$F.write(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
$F.write(..., $INTERM, ...)
- pattern: $A = $F.write(..., request.$W, ...)
- pattern: return $F.write(..., request.$W, ...)
- id: python.django.security.injection.code.user-eval-format-string.user-eval-format-string
message: Found user data in a call to 'eval'. This is extremely dangerous because
it can enable an attacker to execute remote code. See https://owasp.org/www-community/attacks/Code_Injection
for more information.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html
category: security
technology:
- django
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.django.security.injection.code.user-eval-format-string.user-eval-format-string
shortlink: https://sg.run/4x2z
semgrep.dev:
rule:
r_id: 9500
rv_id: 1263383
rule_id: BYUNw9
version_id: vdT06xG
url: https://semgrep.dev/playground/r/vdT06xG/python.django.security.injection.code.user-eval-format-string.user-eval-format-string
origin: community
patterns:
- pattern-inside: |
def $F(...):
...
- pattern-either:
- pattern: eval(..., $STR % request.$W.get(...), ...)
- pattern: |
$V = request.$W.get(...)
...
eval(..., $STR % $V, ...)
- pattern: |
$V = request.$W.get(...)
...
$S = $STR % $V
...
eval(..., $S, ...)
- pattern: eval(..., "..." % request.$W(...), ...)
- pattern: |
$V = request.$W(...)
...
eval(..., $STR % $V, ...)
- pattern: |
$V = request.$W(...)
...
$S = $STR % $V
...
eval(..., $S, ...)
- pattern: eval(..., $STR % request.$W[...], ...)
- pattern: |
$V = request.$W[...]
...
eval(..., $STR % $V, ...)
- pattern: |
$V = request.$W[...]
...
$S = $STR % $V
...
eval(..., $S, ...)
- pattern: eval(..., $STR.format(..., request.$W.get(...), ...), ...)
- pattern: |
$V = request.$W.get(...)
...
eval(..., $STR.format(..., $V, ...), ...)
- pattern: |
$V = request.$W.get(...)
...
$S = $STR.format(..., $V, ...)
...
eval(..., $S, ...)
- pattern: eval(..., $STR.format(..., request.$W(...), ...), ...)
- pattern: |
$V = request.$W(...)
...
eval(..., $STR.format(..., $V, ...), ...)
- pattern: |
$V = request.$W(...)
...
$S = $STR.format(..., $V, ...)
...
eval(..., $S, ...)
- pattern: eval(..., $STR.format(..., request.$W[...], ...), ...)
- pattern: |
$V = request.$W[...]
...
eval(..., $STR.format(..., $V, ...), ...)
- pattern: |
$V = request.$W[...]
...
$S = $STR.format(..., $V, ...)
...
eval(..., $S, ...)
- pattern: |
$V = request.$W.get(...)
...
eval(..., f"...{$V}...", ...)
- pattern: |
$V = request.$W.get(...)
...
$S = f"...{$V}..."
...
eval(..., $S, ...)
- pattern: |
$V = request.$W(...)
...
eval(..., f"...{$V}...", ...)
- pattern: |
$V = request.$W(...)
...
$S = f"...{$V}..."
...
eval(..., $S, ...)
- pattern: |
$V = request.$W[...]
...
eval(..., f"...{$V}...", ...)
- pattern: |
$V = request.$W[...]
...
$S = f"...{$V}..."
...
eval(..., $S, ...)
languages:
- python
severity: WARNING
- id: python.django.security.injection.code.user-eval.user-eval
message: Found user data in a call to 'eval'. This is extremely dangerous because
it can enable an attacker to execute arbitrary remote code on the system. Instead,
refactor your code to not use 'eval' and instead use a safe library for the specific
functionality you need.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html
- https://owasp.org/www-community/attacks/Code_Injection
category: security
technology:
- django
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.django.security.injection.code.user-eval.user-eval
shortlink: https://sg.run/PJDW
semgrep.dev:
rule:
r_id: 9501
rv_id: 1263384
rule_id: DbUpDQ
version_id: d6Tyx2A
url: https://semgrep.dev/playground/r/d6Tyx2A/python.django.security.injection.code.user-eval.user-eval
origin: community
patterns:
- pattern-inside: |
def $F(...):
...
- pattern-either:
- pattern: eval(..., request.$W.get(...), ...)
- pattern: |
$V = request.$W.get(...)
...
eval(..., $V, ...)
- pattern: eval(..., request.$W(...), ...)
- pattern: |
$V = request.$W(...)
...
eval(..., $V, ...)
- pattern: eval(..., request.$W[...], ...)
- pattern: |
$V = request.$W[...]
...
eval(..., $V, ...)
languages:
- python
severity: WARNING
- id: python.django.security.injection.code.user-exec-format-string.user-exec-format-string
message: Found user data in a call to 'exec'. This is extremely dangerous because
it can enable an attacker to execute arbitrary remote code on the system. Instead,
refactor your code to not use 'eval' and instead use a safe library for the specific
functionality you need.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- django
references:
- https://owasp.org/www-community/attacks/Code_Injection
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.django.security.injection.code.user-exec-format-string.user-exec-format-string
shortlink: https://sg.run/J9JW
semgrep.dev:
rule:
r_id: 9502
rv_id: 1263385
rule_id: WAUovx
version_id: ZRTKA1p
url: https://semgrep.dev/playground/r/ZRTKA1p/python.django.security.injection.code.user-exec-format-string.user-exec-format-string
origin: community
patterns:
- pattern-inside: |
def $F(...):
...
- pattern-either:
- pattern: exec(..., $STR % request.$W.get(...), ...)
- pattern: |
$V = request.$W.get(...)
...
exec(..., $STR % $V, ...)
- pattern: |
$V = request.$W.get(...)
...
$S = $STR % $V
...
exec(..., $S, ...)
- pattern: exec(..., "..." % request.$W(...), ...)
- pattern: |
$V = request.$W(...)
...
exec(..., $STR % $V, ...)
- pattern: |
$V = request.$W(...)
...
$S = $STR % $V
...
exec(..., $S, ...)
- pattern: exec(..., $STR % request.$W[...], ...)
- pattern: |
$V = request.$W[...]
...
exec(..., $STR % $V, ...)
- pattern: |
$V = request.$W[...]
...
$S = $STR % $V
...
exec(..., $S, ...)
- pattern: exec(..., $STR.format(..., request.$W.get(...), ...), ...)
- pattern: |
$V = request.$W.get(...)
...
exec(..., $STR.format(..., $V, ...), ...)
- pattern: |
$V = request.$W.get(...)
...
$S = $STR.format(..., $V, ...)
...
exec(..., $S, ...)
- pattern: exec(..., $STR.format(..., request.$W(...), ...), ...)
- pattern: |
$V = request.$W(...)
...
exec(..., $STR.format(..., $V, ...), ...)
- pattern: |
$V = request.$W(...)
...
$S = $STR.format(..., $V, ...)
...
exec(..., $S, ...)
- pattern: exec(..., $STR.format(..., request.$W[...], ...), ...)
- pattern: |
$V = request.$W[...]
...
exec(..., $STR.format(..., $V, ...), ...)
- pattern: |
$V = request.$W[...]
...
$S = $STR.format(..., $V, ...)
...
exec(..., $S, ...)
- pattern: |
$V = request.$W.get(...)
...
exec(..., f"...{$V}...", ...)
- pattern: |
$V = request.$W.get(...)
...
$S = f"...{$V}..."
...
exec(..., $S, ...)
- pattern: |
$V = request.$W(...)
...
exec(..., f"...{$V}...", ...)
- pattern: |
$V = request.$W(...)
...
$S = f"...{$V}..."
...
exec(..., $S, ...)
- pattern: |
$V = request.$W[...]
...
exec(..., f"...{$V}...", ...)
- pattern: |
$V = request.$W[...]
...
$S = f"...{$V}..."
...
exec(..., $S, ...)
- pattern: exec(..., base64.decodestring($S.format(..., request.$W.get(...), ...),
...), ...)
- pattern: exec(..., base64.decodestring($S % request.$W.get(...), ...), ...)
- pattern: exec(..., base64.decodestring(f"...{request.$W.get(...)}...", ...),
...)
- pattern: exec(..., base64.decodestring(request.$W.get(...), ...), ...)
- pattern: exec(..., base64.decodestring(bytes($S.format(..., request.$W.get(...),
...), ...), ...), ...)
- pattern: exec(..., base64.decodestring(bytes($S % request.$W.get(...), ...),
...), ...)
- pattern: exec(..., base64.decodestring(bytes(f"...{request.$W.get(...)}...",
...), ...), ...)
- pattern: exec(..., base64.decodestring(bytes(request.$W.get(...), ...), ...),
...)
- pattern: |
$DATA = request.$W.get(...)
...
exec(..., base64.decodestring($DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = base64.decodestring($DATA, ...)
...
exec(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
exec(..., base64.decodestring(bytes($DATA, ...), ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = base64.decodestring(bytes($DATA, ...), ...)
...
exec(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
exec(..., base64.decodestring($DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = base64.decodestring($DATA, ...)
...
exec(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
exec(..., base64.decodestring(bytes($DATA, ...), ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = base64.decodestring(bytes($DATA, ...), ...)
...
exec(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
exec(..., base64.decodestring($DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = base64.decodestring($DATA, ...)
...
exec(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
exec(..., base64.decodestring(bytes($DATA, ...), ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = base64.decodestring(bytes($DATA, ...), ...)
...
exec(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
exec(..., base64.decodestring($DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = base64.decodestring($DATA, ...)
...
exec(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
exec(..., base64.decodestring(bytes($DATA, ...), ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = base64.decodestring(bytes($DATA, ...), ...)
...
exec(..., $INTERM, ...)
languages:
- python
severity: WARNING
- id: python.django.security.injection.code.user-exec.user-exec
message: Found user data in a call to 'exec'. This is extremely dangerous because
it can enable an attacker to execute arbitrary remote code on the system. Instead,
refactor your code to not use 'eval' and instead use a safe library for the specific
functionality you need.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- django
references:
- https://owasp.org/www-community/attacks/Code_Injection
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.django.security.injection.code.user-exec.user-exec
shortlink: https://sg.run/5Q3X
semgrep.dev:
rule:
r_id: 9503
rv_id: 1263386
rule_id: 0oU5AW
version_id: nWT2LA2
url: https://semgrep.dev/playground/r/nWT2LA2/python.django.security.injection.code.user-exec.user-exec
origin: community
patterns:
- pattern-inside: |
def $F(...):
...
- pattern-either:
- pattern: exec(..., request.$W.get(...), ...)
- pattern: |
$V = request.$W.get(...)
...
exec(..., $V, ...)
- pattern: exec(..., request.$W(...), ...)
- pattern: |
$V = request.$W(...)
...
exec(..., $V, ...)
- pattern: exec(..., request.$W[...], ...)
- pattern: |
$V = request.$W[...]
...
exec(..., $V, ...)
- pattern: |
loop = asyncio.get_running_loop()
...
await loop.run_in_executor(None, exec, request.$W[...])
- pattern: |
$V = request.$W[...]
...
loop = asyncio.get_running_loop()
...
await loop.run_in_executor(None, exec, $V)
- pattern: |
loop = asyncio.get_running_loop()
...
await loop.run_in_executor(None, exec, request.$W.get(...))
- pattern: |
$V = request.$W.get(...)
...
loop = asyncio.get_running_loop()
...
await loop.run_in_executor(None, exec, $V)
languages:
- python
severity: WARNING
- id: python.django.security.injection.command.command-injection-os-system.command-injection-os-system
message: Request data detected in os.system. This could be vulnerable to a command
injection and should be avoided. If this must be done, use the 'subprocess' module
instead and pass the arguments as a list. See https://owasp.org/www-community/attacks/Command_Injection
for more information.
metadata:
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/www-community/attacks/Command_Injection
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.django.security.injection.command.command-injection-os-system.command-injection-os-system
shortlink: https://sg.run/Gen2
semgrep.dev:
rule:
r_id: 9504
rv_id: 1263387
rule_id: KxUbp2
version_id: ExTExPo
url: https://semgrep.dev/playground/r/ExTExPo/python.django.security.injection.command.command-injection-os-system.command-injection-os-system
origin: community
languages:
- python
severity: ERROR
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: os.system(..., request.$W.get(...), ...)
- pattern: os.system(..., $S.format(..., request.$W.get(...), ...), ...)
- pattern: os.system(..., $S % request.$W.get(...), ...)
- pattern: os.system(..., f"...{request.$W.get(...)}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
os.system(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
os.system(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
os.system(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
os.system(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
os.system(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
os.system(..., $INTERM, ...)
- pattern: $A = os.system(..., request.$W.get(...), ...)
- pattern: $A = os.system(..., $S.format(..., request.$W.get(...), ...), ...)
- pattern: $A = os.system(..., $S % request.$W.get(...), ...)
- pattern: $A = os.system(..., f"...{request.$W.get(...)}...", ...)
- pattern: return os.system(..., request.$W.get(...), ...)
- pattern: return os.system(..., $S.format(..., request.$W.get(...), ...), ...)
- pattern: return os.system(..., $S % request.$W.get(...), ...)
- pattern: return os.system(..., f"...{request.$W.get(...)}...", ...)
- pattern: os.system(..., request.$W(...), ...)
- pattern: os.system(..., $S.format(..., request.$W(...), ...), ...)
- pattern: os.system(..., $S % request.$W(...), ...)
- pattern: os.system(..., f"...{request.$W(...)}...", ...)
- pattern: |
$DATA = request.$W(...)
...
os.system(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
os.system(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
os.system(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
os.system(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
os.system(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
os.system(..., $INTERM, ...)
- pattern: $A = os.system(..., request.$W(...), ...)
- pattern: $A = os.system(..., $S.format(..., request.$W(...), ...), ...)
- pattern: $A = os.system(..., $S % request.$W(...), ...)
- pattern: $A = os.system(..., f"...{request.$W(...)}...", ...)
- pattern: return os.system(..., request.$W(...), ...)
- pattern: return os.system(..., $S.format(..., request.$W(...), ...), ...)
- pattern: return os.system(..., $S % request.$W(...), ...)
- pattern: return os.system(..., f"...{request.$W(...)}...", ...)
- pattern: os.system(..., request.$W[...], ...)
- pattern: os.system(..., $S.format(..., request.$W[...], ...), ...)
- pattern: os.system(..., $S % request.$W[...], ...)
- pattern: os.system(..., f"...{request.$W[...]}...", ...)
- pattern: |
$DATA = request.$W[...]
...
os.system(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
os.system(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
os.system(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
os.system(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
os.system(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
os.system(..., $INTERM, ...)
- pattern: $A = os.system(..., request.$W[...], ...)
- pattern: $A = os.system(..., $S.format(..., request.$W[...], ...), ...)
- pattern: $A = os.system(..., $S % request.$W[...], ...)
- pattern: $A = os.system(..., f"...{request.$W[...]}...", ...)
- pattern: return os.system(..., request.$W[...], ...)
- pattern: return os.system(..., $S.format(..., request.$W[...], ...), ...)
- pattern: return os.system(..., $S % request.$W[...], ...)
- pattern: return os.system(..., f"...{request.$W[...]}...", ...)
- pattern: os.system(..., request.$W, ...)
- pattern: os.system(..., $S.format(..., request.$W, ...), ...)
- pattern: os.system(..., $S % request.$W, ...)
- pattern: os.system(..., f"...{request.$W}...", ...)
- pattern: |
$DATA = request.$W
...
os.system(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
os.system(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
os.system(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
os.system(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
os.system(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
os.system(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
os.system(..., $INTERM, ...)
- pattern: $A = os.system(..., request.$W, ...)
- pattern: $A = os.system(..., $S.format(..., request.$W, ...), ...)
- pattern: $A = os.system(..., $S % request.$W, ...)
- pattern: $A = os.system(..., f"...{request.$W}...", ...)
- pattern: return os.system(..., request.$W, ...)
- pattern: return os.system(..., $S.format(..., request.$W, ...), ...)
- pattern: return os.system(..., $S % request.$W, ...)
- pattern: return os.system(..., f"...{request.$W}...", ...)
- id: python.django.security.injection.email.xss-html-email-body.xss-html-email-body
message: Found request data in an EmailMessage that is set to use HTML. This is
dangerous because HTML emails are susceptible to XSS. An attacker could inject
data into this HTML email, causing XSS.
metadata:
cwe:
- 'CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream
Component (''Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://www.damonkohler.com/2008/12/email-injection.html
category: security
technology:
- django
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/python.django.security.injection.email.xss-html-email-body.xss-html-email-body
shortlink: https://sg.run/RoBe
semgrep.dev:
rule:
r_id: 9505
rv_id: 1263390
rule_id: qNUj02
version_id: 8KT5rOn
url: https://semgrep.dev/playground/r/8KT5rOn/python.django.security.injection.email.xss-html-email-body.xss-html-email-body
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-inside: |
def $FUNC(...):
...
$EMAIL.content_subtype = "html"
...
- pattern-either:
- pattern: django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.core.mail.EmailMessage($SUBJ, $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $B.$C(..., $DATA, ...)
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...)
- pattern: return django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...)
- pattern: django.core.mail.EmailMessage($SUBJ, request.$W(...), ...)
- pattern: |
$DATA = request.$W(...)
...
django.core.mail.EmailMessage($SUBJ, $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $B.$C(..., $DATA, ...)
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W(...), ...)
- pattern: return django.core.mail.EmailMessage($SUBJ, request.$W(...), ...)
- pattern: django.core.mail.EmailMessage($SUBJ, request.$W[...], ...)
- pattern: |
$DATA = request.$W[...]
...
django.core.mail.EmailMessage($SUBJ, $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $B.$C(..., $DATA, ...)
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W[...], ...)
- pattern: return django.core.mail.EmailMessage($SUBJ, request.$W[...], ...)
- pattern: django.core.mail.EmailMessage($SUBJ, request.$W, ...)
- pattern: |
$DATA = request.$W
...
django.core.mail.EmailMessage($SUBJ, $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $B.$C(..., $DATA, ...)
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
django.core.mail.EmailMessage($SUBJ, $INTERM, ...)
- pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W, ...)
- pattern: return django.core.mail.EmailMessage($SUBJ, request.$W, ...)
- id: python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message
message: Found request data in 'send_mail(...)' that uses 'html_message'. This is
dangerous because HTML emails are susceptible to XSS. An attacker could inject
data into this HTML email, causing XSS.
metadata:
cwe:
- 'CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream
Component (''Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://www.damonkohler.com/2008/12/email-injection.html
category: security
technology:
- django
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message
shortlink: https://sg.run/Avx8
semgrep.dev:
rule:
r_id: 9506
rv_id: 1263391
rule_id: lBU9Ll
version_id: gETB7Gn
url: https://semgrep.dev/playground/r/gETB7Gn/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: django.core.mail.send_mail(..., html_message=request.$W.get(...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.core.mail.send_mail(..., html_message=$DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.core.mail.send_mail(..., html_message=$STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.core.mail.send_mail(..., html_message=$STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: $A = django.core.mail.send_mail(..., html_message=request.$W.get(...),
...)
- pattern: return django.core.mail.send_mail(..., html_message=request.$W.get(...),
...)
- pattern: django.core.mail.send_mail(..., html_message=request.$W(...), ...)
- pattern: |
$DATA = request.$W(...)
...
django.core.mail.send_mail(..., html_message=$DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.core.mail.send_mail(..., html_message=$STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.core.mail.send_mail(..., html_message=$STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: $A = django.core.mail.send_mail(..., html_message=request.$W(...),
...)
- pattern: return django.core.mail.send_mail(..., html_message=request.$W(...),
...)
- pattern: django.core.mail.send_mail(..., html_message=request.$W[...], ...)
- pattern: |
$DATA = request.$W[...]
...
django.core.mail.send_mail(..., html_message=$DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.core.mail.send_mail(..., html_message=$STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.core.mail.send_mail(..., html_message=$STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: $A = django.core.mail.send_mail(..., html_message=request.$W[...],
...)
- pattern: return django.core.mail.send_mail(..., html_message=request.$W[...],
...)
- pattern: django.core.mail.send_mail(..., html_message=request.$W, ...)
- pattern: |
$DATA = request.$W
...
django.core.mail.send_mail(..., html_message=$DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.core.mail.send_mail(..., html_message=$STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.core.mail.send_mail(..., html_message=$STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
django.core.mail.send_mail(..., html_message=$INTERM, ...)
- pattern: $A = django.core.mail.send_mail(..., html_message=request.$W, ...)
- pattern: return django.core.mail.send_mail(..., html_message=request.$W, ...)
- id: python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open
message: Found request data in a call to 'open'. Ensure the request data is validated
or sanitized, otherwise it could result in path traversal attacks and therefore
sensitive data being leaked. To mitigate, consider using os.path.abspath or os.path.realpath
or the pathlib library.
metadata:
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://owasp.org/www-community/attacks/Path_Traversal
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open
shortlink: https://sg.run/W8qg
semgrep.dev:
rule:
r_id: 9509
rv_id: 1263396
rule_id: oqUe7z
version_id: JdTzxAw
url: https://semgrep.dev/playground/r/JdTzxAw/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: open(..., request.$W.get(...), ...)
- pattern: open(..., $S.format(..., request.$W.get(...), ...), ...)
- pattern: open(..., $S % request.$W.get(...), ...)
- pattern: open(..., f"...{request.$W.get(...)}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
open(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W.get(...)
...
open(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W.get(...)
...
open(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W.get(...)
...
open(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W.get(...)
...
open(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: $A = open(..., request.$W.get(...), ...)
- pattern: $A = open(..., $S.format(..., request.$W.get(...), ...), ...)
- pattern: $A = open(..., $S % request.$W.get(...), ...)
- pattern: $A = open(..., f"...{request.$W.get(...)}...", ...)
- pattern: return open(..., request.$W.get(...), ...)
- pattern: return open(..., $S.format(..., request.$W.get(...), ...), ...)
- pattern: return open(..., $S % request.$W.get(...), ...)
- pattern: return open(..., f"...{request.$W.get(...)}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
with open(..., $DATA, ...) as $FD:
...
- pattern: open(..., request.$W(...), ...)
- pattern: open(..., $S.format(..., request.$W(...), ...), ...)
- pattern: open(..., $S % request.$W(...), ...)
- pattern: open(..., f"...{request.$W(...)}...", ...)
- pattern: |
$DATA = request.$W(...)
...
open(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W(...)
...
open(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W(...)
...
open(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W(...)
...
open(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W(...)
...
open(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: $A = open(..., request.$W(...), ...)
- pattern: $A = open(..., $S.format(..., request.$W(...), ...), ...)
- pattern: $A = open(..., $S % request.$W(...), ...)
- pattern: $A = open(..., f"...{request.$W(...)}...", ...)
- pattern: return open(..., request.$W(...), ...)
- pattern: return open(..., $S.format(..., request.$W(...), ...), ...)
- pattern: return open(..., $S % request.$W(...), ...)
- pattern: return open(..., f"...{request.$W(...)}...", ...)
- pattern: |
$DATA = request.$W(...)
...
with open(..., $DATA, ...) as $FD:
...
- pattern: open(..., request.$W[...], ...)
- pattern: open(..., $S.format(..., request.$W[...], ...), ...)
- pattern: open(..., $S % request.$W[...], ...)
- pattern: open(..., f"...{request.$W[...]}...", ...)
- pattern: |
$DATA = request.$W[...]
...
open(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W[...]
...
open(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W[...]
...
open(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W[...]
...
open(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W[...]
...
open(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: $A = open(..., request.$W[...], ...)
- pattern: $A = open(..., $S.format(..., request.$W[...], ...), ...)
- pattern: $A = open(..., $S % request.$W[...], ...)
- pattern: $A = open(..., f"...{request.$W[...]}...", ...)
- pattern: return open(..., request.$W[...], ...)
- pattern: return open(..., $S.format(..., request.$W[...], ...), ...)
- pattern: return open(..., $S % request.$W[...], ...)
- pattern: return open(..., f"...{request.$W[...]}...", ...)
- pattern: |
$DATA = request.$W[...]
...
with open(..., $DATA, ...) as $FD:
...
- pattern: open(..., request.$W, ...)
- pattern: open(..., $S.format(..., request.$W, ...), ...)
- pattern: open(..., $S % request.$W, ...)
- pattern: open(..., f"...{request.$W}...", ...)
- pattern: |
$DATA = request.$W
...
open(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W
...
open(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W
...
open(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W
...
open(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: |
$DATA = request.$W
...
open(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
open(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
with open(..., $INTERM, ...) as $FD:
...
- pattern: $A = open(..., request.$W, ...)
- pattern: $A = open(..., $S.format(..., request.$W, ...), ...)
- pattern: $A = open(..., $S % request.$W, ...)
- pattern: $A = open(..., f"...{request.$W}...", ...)
- pattern: return open(..., request.$W, ...)
- pattern: return open(..., $S.format(..., request.$W, ...), ...)
- pattern: return open(..., $S % request.$W, ...)
- pattern: return open(..., f"...{request.$W}...", ...)
- pattern: |
$DATA = request.$W
...
with open(..., $DATA, ...) as $FD:
...
- id: python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where
message: User-controlled data from a request is passed to 'extra()'. This could
lead to a SQL injection and therefore protected information could be leaked. Instead,
use parameterized queries or escape the user-controlled data by using `params`
and not using quote placeholders in the SQL string.
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://docs.djangoproject.com/en/3.0/ref/models/expressions/#.objects.extra
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where
shortlink: https://sg.run/0Ql5
semgrep.dev:
rule:
r_id: 9510
rv_id: 1263402
rule_id: zdUkx1
version_id: DkTRb4l
url: https://semgrep.dev/playground/r/DkTRb4l/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W.get(...),
...), ...], ...)
- pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W.get(...), ...],
...)
- pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W.get(...)}...",
...], ...)
- pattern: $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...],
...)
- pattern: return $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...],
...)
- pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W(...),
...), ...], ...)
- pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W(...), ...], ...)
- pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W(...)}...", ...],
...)
- pattern: $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...)
- pattern: return $MODEL.objects.extra(..., where=[..., request.$W(...), ...],
...)
- pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W[...],
...), ...], ...)
- pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W[...], ...], ...)
- pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W[...]}...", ...],
...)
- pattern: $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...)
- pattern: return $MODEL.objects.extra(..., where=[..., request.$W[...], ...],
...)
- pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W, ...),
...], ...)
- pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W, ...], ...)
- pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W}...", ...],
...)
- pattern: $MODEL.objects.extra(..., where=[..., request.$W, ...], ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W, ...], ...)
- pattern: return $MODEL.objects.extra(..., where=[..., request.$W, ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % (..., $DATA, ...)
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % (..., $DATA, ...)
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % (..., $DATA, ...)
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % (..., $DATA, ...)
...
$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)
- id: python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql
message: User-controlled data from request is passed to 'RawSQL()'. This could lead
to a SQL injection and therefore protected information could be leaked. Instead,
use parameterized queries or escape the user-controlled data by using `params`
and not using quote placeholders in the SQL string.
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://docs.djangoproject.com/en/3.0/ref/models/expressions/#django.db.models.expressions.RawSQL
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql
shortlink: https://sg.run/Kl4X
semgrep.dev:
rule:
r_id: 9511
rv_id: 1263403
rule_id: pKUOBp
version_id: WrTqK2L
url: https://semgrep.dev/playground/r/WrTqK2L/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W.get(...),
...), ...)
- pattern: django.db.models.expressions.RawSQL(..., $S % request.$W.get(...),
...)
- pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W.get(...)}...",
...)
- pattern: django.db.models.expressions.RawSQL(..., request.$W.get(...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.db.models.expressions.RawSQL(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.db.models.expressions.RawSQL(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.db.models.expressions.RawSQL(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: $A = django.db.models.expressions.RawSQL(..., request.$W.get(...),
...)
- pattern: return django.db.models.expressions.RawSQL(..., request.$W.get(...),
...)
- pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W(...),
...), ...)
- pattern: django.db.models.expressions.RawSQL(..., $S % request.$W(...), ...)
- pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W(...)}...",
...)
- pattern: django.db.models.expressions.RawSQL(..., request.$W(...), ...)
- pattern: |
$DATA = request.$W(...)
...
django.db.models.expressions.RawSQL(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.db.models.expressions.RawSQL(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
django.db.models.expressions.RawSQL(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: $A = django.db.models.expressions.RawSQL(..., request.$W(...), ...)
- pattern: return django.db.models.expressions.RawSQL(..., request.$W(...), ...)
- pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W[...],
...), ...)
- pattern: django.db.models.expressions.RawSQL(..., $S % request.$W[...], ...)
- pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W[...]}...",
...)
- pattern: django.db.models.expressions.RawSQL(..., request.$W[...], ...)
- pattern: |
$DATA = request.$W[...]
...
django.db.models.expressions.RawSQL(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.db.models.expressions.RawSQL(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
django.db.models.expressions.RawSQL(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: $A = django.db.models.expressions.RawSQL(..., request.$W[...], ...)
- pattern: return django.db.models.expressions.RawSQL(..., request.$W[...], ...)
- pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W,
...), ...)
- pattern: django.db.models.expressions.RawSQL(..., $S % request.$W, ...)
- pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W}...", ...)
- pattern: django.db.models.expressions.RawSQL(..., request.$W, ...)
- pattern: |
$DATA = request.$W
...
django.db.models.expressions.RawSQL(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.db.models.expressions.RawSQL(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
django.db.models.expressions.RawSQL(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
django.db.models.expressions.RawSQL(..., $INTERM, ...)
- pattern: $A = django.db.models.expressions.RawSQL(..., request.$W, ...)
- pattern: return django.db.models.expressions.RawSQL(..., request.$W, ...)
- pattern: |
$DATA = request.$W.get(...)
...
django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % (..., $DATA, ...)
...
django.db.models.expressions.RawSQL($INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % (..., $DATA, ...)
...
django.db.models.expressions.RawSQL($INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % (..., $DATA, ...)
...
django.db.models.expressions.RawSQL($INTERM, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % (..., $DATA, ...)
...
django.db.models.expressions.RawSQL($INTERM, ...)
- id: python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute
message: User-controlled data from a request is passed to 'execute()'. This could
lead to a SQL injection and therefore protected information could be leaked. Instead,
use django's QuerySets, which are built with query parameterization and therefore
not vulnerable to sql injection. For example, you could use `Entry.objects.filter(date=2006)`.
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute
shortlink: https://sg.run/qx7y
semgrep.dev:
rule:
r_id: 9512
rv_id: 1263404
rule_id: 2ZUbDL
version_id: 0bTKzRj
url: https://semgrep.dev/playground/r/0bTKzRj/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: $CURSOR.execute(..., $S.format(..., request.$W.get(...), ...), ...)
- pattern: $CURSOR.execute(..., $S % request.$W.get(...), ...)
- pattern: $CURSOR.execute(..., f"...{request.$W.get(...)}...", ...)
- pattern: $CURSOR.execute(..., request.$W.get(...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$CURSOR.execute(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$CURSOR.execute(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$CURSOR.execute(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$CURSOR.execute(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: $A = $CURSOR.execute(..., request.$W.get(...), ...)
- pattern: return $CURSOR.execute(..., request.$W.get(...), ...)
- pattern: $CURSOR.execute(..., $S.format(..., request.$W(...), ...), ...)
- pattern: $CURSOR.execute(..., $S % request.$W(...), ...)
- pattern: $CURSOR.execute(..., f"...{request.$W(...)}...", ...)
- pattern: $CURSOR.execute(..., request.$W(...), ...)
- pattern: |
$DATA = request.$W(...)
...
$CURSOR.execute(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$CURSOR.execute(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$CURSOR.execute(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$CURSOR.execute(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: $A = $CURSOR.execute(..., request.$W(...), ...)
- pattern: return $CURSOR.execute(..., request.$W(...), ...)
- pattern: $CURSOR.execute(..., $S.format(..., request.$W[...], ...), ...)
- pattern: $CURSOR.execute(..., $S % request.$W[...], ...)
- pattern: $CURSOR.execute(..., f"...{request.$W[...]}...", ...)
- pattern: $CURSOR.execute(..., request.$W[...], ...)
- pattern: |
$DATA = request.$W[...]
...
$CURSOR.execute(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$CURSOR.execute(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$CURSOR.execute(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$CURSOR.execute(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: $A = $CURSOR.execute(..., request.$W[...], ...)
- pattern: return $CURSOR.execute(..., request.$W[...], ...)
- pattern: $CURSOR.execute(..., $S.format(..., request.$W, ...), ...)
- pattern: $CURSOR.execute(..., $S % request.$W, ...)
- pattern: $CURSOR.execute(..., f"...{request.$W}...", ...)
- pattern: $CURSOR.execute(..., request.$W, ...)
- pattern: |
$DATA = request.$W
...
$CURSOR.execute(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$CURSOR.execute(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$CURSOR.execute(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$CURSOR.execute(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
$CURSOR.execute(..., $INTERM, ...)
- pattern: $A = $CURSOR.execute(..., request.$W, ...)
- pattern: return $CURSOR.execute(..., request.$W, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$CURSOR.execute($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$CURSOR.execute($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$CURSOR.execute($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$CURSOR.execute($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % (..., $DATA, ...)
...
$CURSOR.execute($INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % (..., $DATA, ...)
...
$CURSOR.execute($INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % (..., $DATA, ...)
...
$CURSOR.execute($INTERM, ...)
- pattern: |-
$DATA = request.$W
...
$INTERM = $STR % (..., $DATA, ...)
...
$CURSOR.execute($INTERM, ...)
- id: python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw
message: Data that is possible user-controlled from a python request is passed to
`raw()`. This could lead to SQL injection and attackers gaining access to protected
information. Instead, use django's QuerySets, which are built with query parameterization
and therefore not vulnerable to sql injection. For example, you could use `Entry.objects.filter(date=2006)`.
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw
shortlink: https://sg.run/l2v9
semgrep.dev:
rule:
r_id: 9513
rv_id: 1263405
rule_id: X5U8v5
version_id: K3TKkBW
url: https://semgrep.dev/playground/r/K3TKkBW/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: $MODEL.objects.raw(..., $S.format(..., request.$W.get(...), ...), ...)
- pattern: $MODEL.objects.raw(..., $S % request.$W.get(...), ...)
- pattern: $MODEL.objects.raw(..., f"...{request.$W.get(...)}...", ...)
- pattern: $MODEL.objects.raw(..., request.$W.get(...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.raw(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.raw(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.raw(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.raw(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: $A = $MODEL.objects.raw(..., request.$W.get(...), ...)
- pattern: return $MODEL.objects.raw(..., request.$W.get(...), ...)
- pattern: $MODEL.objects.raw(..., $S.format(..., request.$W(...), ...), ...)
- pattern: $MODEL.objects.raw(..., $S % request.$W(...), ...)
- pattern: $MODEL.objects.raw(..., f"...{request.$W(...)}...", ...)
- pattern: $MODEL.objects.raw(..., request.$W(...), ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.raw(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.raw(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.raw(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.raw(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: $A = $MODEL.objects.raw(..., request.$W(...), ...)
- pattern: return $MODEL.objects.raw(..., request.$W(...), ...)
- pattern: $MODEL.objects.raw(..., $S.format(..., request.$W[...], ...), ...)
- pattern: $MODEL.objects.raw(..., $S % request.$W[...], ...)
- pattern: $MODEL.objects.raw(..., f"...{request.$W[...]}...", ...)
- pattern: $MODEL.objects.raw(..., request.$W[...], ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.raw(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.raw(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.raw(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.raw(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: $A = $MODEL.objects.raw(..., request.$W[...], ...)
- pattern: return $MODEL.objects.raw(..., request.$W[...], ...)
- pattern: $MODEL.objects.raw(..., $S.format(..., request.$W, ...), ...)
- pattern: $MODEL.objects.raw(..., $S % request.$W, ...)
- pattern: $MODEL.objects.raw(..., f"...{request.$W}...", ...)
- pattern: $MODEL.objects.raw(..., request.$W, ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.raw(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.raw(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.raw(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.raw(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
$MODEL.objects.raw(..., $INTERM, ...)
- pattern: $A = $MODEL.objects.raw(..., request.$W, ...)
- pattern: return $MODEL.objects.raw(..., request.$W, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$MODEL.objects.raw($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$MODEL.objects.raw($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$MODEL.objects.raw($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$MODEL.objects.raw($STR % (..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % (..., $DATA, ...)
...
$MODEL.objects.raw($INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % (..., $DATA, ...)
...
$MODEL.objects.raw($INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % (..., $DATA, ...)
...
$MODEL.objects.raw($INTERM, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % (..., $DATA, ...)
...
$MODEL.objects.raw($INTERM, ...)
- id: python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests
message: Data from request object is passed to a new server-side request. This could
lead to a server-side request forgery (SSRF). To mitigate, ensure that schemes
and hosts are validated against an allowlist, do not forward the response to the
user, and ensure proper authentication and transport-layer security in the proxied
request. See https://owasp.org/www-community/attacks/Server_Side_Request_Forgery
to learn more about SSRF vulnerabilities.
metadata:
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
references:
- https://owasp.org/www-community/attacks/Server_Side_Request_Forgery
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests
shortlink: https://sg.run/YvY4
semgrep.dev:
rule:
r_id: 9514
rv_id: 1263406
rule_id: j2UvEw
version_id: qkTR7zn
url: https://semgrep.dev/playground/r/qkTR7zn/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests
origin: community
languages:
- python
severity: ERROR
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: requests.$METHOD(..., $S.format(..., request.$W.get(...), ...), ...)
- pattern: requests.$METHOD(..., $S % request.$W.get(...), ...)
- pattern: requests.$METHOD(..., f"...{request.$W.get(...)}...", ...)
- pattern: requests.$METHOD(..., request.$W.get(...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
requests.$METHOD(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
requests.$METHOD(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
requests.$METHOD(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
requests.$METHOD(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
requests.$METHOD(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: $A = requests.$METHOD(..., request.$W.get(...), ...)
- pattern: return requests.$METHOD(..., request.$W.get(...), ...)
- pattern: requests.$METHOD(..., $S.format(..., request.$W(...), ...), ...)
- pattern: requests.$METHOD(..., $S % request.$W(...), ...)
- pattern: requests.$METHOD(..., f"...{request.$W(...)}...", ...)
- pattern: requests.$METHOD(..., request.$W(...), ...)
- pattern: |
$DATA = request.$W(...)
...
requests.$METHOD(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
requests.$METHOD(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
requests.$METHOD(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
requests.$METHOD(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
requests.$METHOD(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: $A = requests.$METHOD(..., request.$W(...), ...)
- pattern: return requests.$METHOD(..., request.$W(...), ...)
- pattern: requests.$METHOD(..., $S.format(..., request.$W[...], ...), ...)
- pattern: requests.$METHOD(..., $S % request.$W[...], ...)
- pattern: requests.$METHOD(..., f"...{request.$W[...]}...", ...)
- pattern: requests.$METHOD(..., request.$W[...], ...)
- pattern: |
$DATA = request.$W[...]
...
requests.$METHOD(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
requests.$METHOD(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
requests.$METHOD(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
requests.$METHOD(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
requests.$METHOD(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: $A = requests.$METHOD(..., request.$W[...], ...)
- pattern: return requests.$METHOD(..., request.$W[...], ...)
- pattern: requests.$METHOD(..., $S.format(..., request.$W, ...), ...)
- pattern: requests.$METHOD(..., $S % request.$W, ...)
- pattern: requests.$METHOD(..., f"...{request.$W}...", ...)
- pattern: requests.$METHOD(..., request.$W, ...)
- pattern: |
$DATA = request.$W
...
requests.$METHOD(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
requests.$METHOD(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
requests.$METHOD(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
requests.$METHOD(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
requests.$METHOD(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
requests.$METHOD(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
requests.$METHOD(..., $INTERM, ...)
- pattern: $A = requests.$METHOD(..., request.$W, ...)
- pattern: return requests.$METHOD(..., request.$W, ...)
- id: python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib
message: Data from request object is passed to a new server-side request. This could
lead to a server-side request forgery (SSRF), which could result in attackers
gaining access to private organization data. To mitigate, ensure that schemes
and hosts are validated against an allowlist, do not forward the response to the
user, and ensure proper authentication and transport-layer security in the proxied
request.
metadata:
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
references:
- https://owasp.org/www-community/attacks/Server_Side_Request_Forgery
category: security
technology:
- django
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib
shortlink: https://sg.run/6n2B
semgrep.dev:
rule:
r_id: 9515
rv_id: 1263407
rule_id: 10UKDo
version_id: l4TJRwD
url: https://semgrep.dev/playground/r/l4TJRwD/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib
origin: community
languages:
- python
severity: ERROR
patterns:
- pattern-inside: |
def $FUNC(...):
...
- pattern-either:
- pattern: urllib.request.urlopen(..., $S.format(..., request.$W.get(...), ...),
...)
- pattern: urllib.request.urlopen(..., $S % request.$W.get(...), ...)
- pattern: urllib.request.urlopen(..., f"...{request.$W.get(...)}...", ...)
- pattern: urllib.request.urlopen(..., request.$W.get(...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
urllib.request.urlopen(..., $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
urllib.request.urlopen(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR % $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
urllib.request.urlopen(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = f"...{$DATA}..."
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W.get(...)
...
urllib.request.urlopen(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W.get(...)
...
$INTERM = $STR + $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: $A = urllib.request.urlopen(..., request.$W.get(...), ...)
- pattern: return urllib.request.urlopen(..., request.$W.get(...), ...)
- pattern: urllib.request.urlopen(..., $S.format(..., request.$W(...), ...), ...)
- pattern: urllib.request.urlopen(..., $S % request.$W(...), ...)
- pattern: urllib.request.urlopen(..., f"...{request.$W(...)}...", ...)
- pattern: urllib.request.urlopen(..., request.$W(...), ...)
- pattern: |
$DATA = request.$W(...)
...
urllib.request.urlopen(..., $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR.format(..., $DATA, ...)
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
urllib.request.urlopen(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR % $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
urllib.request.urlopen(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = f"...{$DATA}..."
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W(...)
...
urllib.request.urlopen(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W(...)
...
$INTERM = $STR + $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: $A = urllib.request.urlopen(..., request.$W(...), ...)
- pattern: return urllib.request.urlopen(..., request.$W(...), ...)
- pattern: urllib.request.urlopen(..., $S.format(..., request.$W[...], ...), ...)
- pattern: urllib.request.urlopen(..., $S % request.$W[...], ...)
- pattern: urllib.request.urlopen(..., f"...{request.$W[...]}...", ...)
- pattern: urllib.request.urlopen(..., request.$W[...], ...)
- pattern: |
$DATA = request.$W[...]
...
urllib.request.urlopen(..., $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR.format(..., $DATA, ...)
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
urllib.request.urlopen(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR % $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
urllib.request.urlopen(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = f"...{$DATA}..."
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W[...]
...
urllib.request.urlopen(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W[...]
...
$INTERM = $STR + $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: $A = urllib.request.urlopen(..., request.$W[...], ...)
- pattern: return urllib.request.urlopen(..., request.$W[...], ...)
- pattern: urllib.request.urlopen(..., $S.format(..., request.$W, ...), ...)
- pattern: urllib.request.urlopen(..., $S % request.$W, ...)
- pattern: urllib.request.urlopen(..., f"...{request.$W}...", ...)
- pattern: urllib.request.urlopen(..., request.$W, ...)
- pattern: |
$DATA = request.$W
...
urllib.request.urlopen(..., $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR.format(..., $DATA, ...)
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
urllib.request.urlopen(..., $STR % $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR % $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
urllib.request.urlopen(..., f"...{$DATA}...", ...)
- pattern: |
$DATA = request.$W
...
$INTERM = f"...{$DATA}..."
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: |
$DATA = request.$W
...
urllib.request.urlopen(..., $STR + $DATA, ...)
- pattern: |
$DATA = request.$W
...
$INTERM = $STR + $DATA
...
urllib.request.urlopen(..., $INTERM, ...)
- pattern: $A = urllib.request.urlopen(..., request.$W, ...)
- pattern: return urllib.request.urlopen(..., request.$W, ...)
- id: python.django.security.passwords.password-empty-string.password-empty-string
message: '''$VAR'' is the empty string and is being used to set the password on
''$MODEL''. If you meant to set an unusable password, set the password to None
or call ''set_unusable_password()''.'
metadata:
cwe:
- 'CWE-521: Weak Password Requirements'
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
references:
- https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password
category: security
technology:
- django
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/python.django.security.passwords.password-empty-string.password-empty-string
shortlink: https://sg.run/oxnR
semgrep.dev:
rule:
r_id: 9516
rv_id: 1263411
rule_id: 9AU1jW
version_id: GxTke5Q
url: https://semgrep.dev/playground/r/GxTke5Q/python.django.security.passwords.password-empty-string.password-empty-string
origin: community
patterns:
- pattern-either:
- pattern: |
$MODEL.set_password($EMPTY)
...
$MODEL.save()
- pattern: |
$VAR = $EMPTY
...
$MODEL.set_password($VAR)
...
$MODEL.save()
- metavariable-regex:
metavariable: $EMPTY
regex: (\'\'|\"\")
languages:
- python
severity: ERROR
- id: python.django.security.passwords.use-none-for-password-default.use-none-for-password-default
message: '''$VAR'' is using the empty string as its default and is being used to
set the password on ''$MODEL''. If you meant to set an unusable password, set
the default value to ''None'' or call ''set_unusable_password()''.'
metadata:
cwe:
- 'CWE-521: Weak Password Requirements'
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
references:
- https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password
category: security
technology:
- django
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default
shortlink: https://sg.run/zvBW
semgrep.dev:
rule:
r_id: 9517
rv_id: 1263412
rule_id: yyUn6Z
version_id: RGT0LYX
url: https://semgrep.dev/playground/r/RGT0LYX/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default
origin: community
languages:
- python
severity: ERROR
patterns:
- pattern-either:
- pattern: |
$VAR = request.$W.get($X, $EMPTY)
...
$MODEL.set_password($VAR)
...
$MODEL.save(...)
- pattern: |
def $F(..., $VAR=$EMPTY, ...):
...
$MODEL.set_password($VAR)
- metavariable-pattern:
metavariable: $EMPTY
pattern: '""'
- focus-metavariable: $EMPTY
fix: |
None
- id: python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host
message: Running flask app with host 0.0.0.0 could expose the server publicly.
metadata:
cwe:
- 'CWE-668: Exposure of Resource to Wrong Sphere'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
category: security
technology:
- flask
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host
shortlink: https://sg.run/eLby
semgrep.dev:
rule:
r_id: 9532
rv_id: 1263414
rule_id: L1Uy1n
version_id: BjTkZOY
url: https://semgrep.dev/playground/r/BjTkZOY/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host
origin: community
languages:
- python
severity: WARNING
pattern-either:
- pattern: app.run(..., host="0.0.0.0", ...)
- pattern: app.run(..., "0.0.0.0", ...)
- id: python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly
patterns:
- pattern-not-inside: |
if __name__ == '__main__':
...
- pattern-not-inside: |
def $X(...):
...
- pattern: app.run(...)
message: top-level app.run(...) is ignored by flask. Consider putting app.run(...)
behind a guard, like inside a function
metadata:
cwe:
- 'CWE-668: Exposure of Resource to Wrong Sphere'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
category: security
technology:
- flask
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly
shortlink: https://sg.run/vz5b
semgrep.dev:
rule:
r_id: 9533
rv_id: 1263415
rule_id: 8GUjdX
version_id: DkTRb4z
url: https://semgrep.dev/playground/r/DkTRb4z/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly
origin: community
languages:
- python
severity: WARNING
- id: python.flask.security.audit.debug-enabled.debug-enabled
patterns:
- pattern-inside: |
import flask
...
- pattern: $APP.run(..., debug=True, ...)
message: Detected Flask app with debug=True. Do not deploy to production with this
flag enabled as it will leak sensitive information. Instead, consider using Flask
configuration variables or setting 'debug' using system environment variables.
metadata:
cwe:
- 'CWE-489: Active Debug Code'
owasp: A06:2017 - Security Misconfiguration
references:
- https://labs.detectify.com/2015/10/02/how-patreon-got-hacked-publicly-exposed-werkzeug-debugger/
category: security
technology:
- flask
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Active Debug Code
source: https://semgrep.dev/r/python.flask.security.audit.debug-enabled.debug-enabled
shortlink: https://sg.run/dKrd
semgrep.dev:
rule:
r_id: 9534
rv_id: 946206
rule_id: gxU1bd
version_id: 8KTKjwR
url: https://semgrep.dev/playground/r/8KTKjwR/python.flask.security.audit.debug-enabled.debug-enabled
origin: community
severity: WARNING
languages:
- python
- id: python.flask.security.audit.directly-returned-format-string.directly-returned-format-string
message: Detected Flask route directly returning a formatted string. This is subject
to cross-site scripting if user input can reach the string. Consider using the
template engine instead and rendering pages with 'render_template()'.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- flask
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string
shortlink: https://sg.run/Zv6o
semgrep.dev:
rule:
r_id: 9535
rv_id: 1263416
rule_id: QrUz49
version_id: WrTqKAz
url: https://semgrep.dev/playground/r/WrTqKAz/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string
origin: community
languages:
- python
severity: WARNING
mode: taint
pattern-sources:
- pattern-either:
- patterns:
- pattern-inside: |
@$APP.route(...)
def $FUNC(..., $PARAM, ...):
...
- pattern: $PARAM
- pattern: |
request.$FUNC.get(...)
- pattern: |
request.$FUNC(...)
- pattern: request.$FUNC[...]
pattern-sinks:
- patterns:
- pattern-not-inside: return "..."
- pattern-either:
- pattern: return "...".format(...)
- pattern: return "..." % ...
- pattern: return "..." + ...
- pattern: return ... + "..."
- pattern: return f"...{...}..."
- patterns:
- pattern: return $X
- pattern-either:
- pattern-inside: |
$X = "...".format(...)
...
- pattern-inside: |
$X = "..." % ...
...
- pattern-inside: |
$X = "..." + ...
...
- pattern-inside: |
$X = ... + "..."
...
- pattern-inside: |
$X = f"...{...}..."
...
- pattern-not-inside: |
$X = "..."
...
- id: python.flask.security.injection.os-system-injection.os-system-injection
languages:
- python
severity: ERROR
message: User data detected in os.system. This could be vulnerable to a command
injection and should be avoided. If this must be done, use the 'subprocess' module
instead and pass the arguments as a list.
metadata:
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/www-community/attacks/Command_Injection
category: security
technology:
- flask
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.flask.security.injection.os-system-injection.os-system-injection
shortlink: https://sg.run/4xzz
semgrep.dev:
rule:
r_id: 9544
rv_id: 1263429
rule_id: BYUN99
version_id: 1QTypw7
url: https://semgrep.dev/playground/r/1QTypw7/python.flask.security.injection.os-system-injection.os-system-injection
origin: community
pattern-either:
- patterns:
- pattern: os.system(...)
- pattern-either:
- pattern-inside: |
@$APP.route($ROUTE, ...)
def $FUNC(..., $ROUTEVAR, ...):
...
os.system(..., <... $ROUTEVAR ...>, ...)
- pattern-inside: |
@$APP.route($ROUTE, ...)
def $FUNC(..., $ROUTEVAR, ...):
...
$INTERM = <... $ROUTEVAR ...>
...
os.system(..., <... $INTERM ...>, ...)
- pattern: os.system(..., <... flask.request.$W.get(...) ...>, ...)
- pattern: os.system(..., <... flask.request.$W[...] ...>, ...)
- pattern: os.system(..., <... flask.request.$W(...) ...>, ...)
- pattern: os.system(..., <... flask.request.$W ...>, ...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W.get(...) ...>
...
os.system(<... $INTERM ...>)
- pattern: os.system(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W[...] ...>
...
os.system(<... $INTERM ...>)
- pattern: os.system(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W(...) ...>
...
os.system(<... $INTERM ...>)
- pattern: os.system(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W ...>
...
os.system(<... $INTERM ...>)
- pattern: os.system(...)
- id: python.flask.security.injection.path-traversal-open.path-traversal-open
languages:
- python
severity: ERROR
message: Found request data in a call to 'open'. Ensure the request data is validated
or sanitized, otherwise it could result in path traversal attacks.
metadata:
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://owasp.org/www-community/attacks/Path_Traversal
category: security
technology:
- flask
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/python.flask.security.injection.path-traversal-open.path-traversal-open
shortlink: https://sg.run/PJRW
semgrep.dev:
rule:
r_id: 9545
rv_id: 1263430
rule_id: DbUpOQ
version_id: 9lT4b94
url: https://semgrep.dev/playground/r/9lT4b94/python.flask.security.injection.path-traversal-open.path-traversal-open
origin: community
pattern-either:
- patterns:
- pattern: open(...)
- pattern-either:
- pattern-inside: |
@$APP.route($ROUTE, ...)
def $FUNC(..., $ROUTEVAR, ...):
...
open(..., <... $ROUTEVAR ...>, ...)
- pattern-inside: |
@$APP.route($ROUTE, ...)
def $FUNC(..., $ROUTEVAR, ...):
...
with open(..., <... $ROUTEVAR ...>, ...) as $FD:
...
- pattern-inside: |
@$APP.route($ROUTE, ...)
def $FUNC(..., $ROUTEVAR, ...):
...
$INTERM = <... $ROUTEVAR ...>
...
open(..., <... $INTERM ...>, ...)
- pattern: open(..., <... flask.request.$W.get(...) ...>, ...)
- pattern: open(..., <... flask.request.$W[...] ...>, ...)
- pattern: open(..., <... flask.request.$W(...) ...>, ...)
- pattern: open(..., <... flask.request.$W ...>, ...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W.get(...) ...>
...
open(<... $INTERM ...>, ...)
- pattern: open(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W[...] ...>
...
open(<... $INTERM ...>, ...)
- pattern: open(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W(...) ...>
...
open(<... $INTERM ...>, ...)
- pattern: open(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W ...>
...
open(<... $INTERM ...>, ...)
- pattern: open(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W.get(...) ...>
...
with open(<... $INTERM ...>, ...) as $F:
...
- pattern: open(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W[...] ...>
...
with open(<... $INTERM ...>, ...) as $F:
...
- pattern: open(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W(...) ...>
...
with open(<... $INTERM ...>, ...) as $F:
...
- pattern: open(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W ...>
...
with open(<... $INTERM ...>, ...) as $F:
...
- pattern: open(...)
- id: python.flask.security.injection.ssrf-requests.ssrf-requests
languages:
- python
severity: ERROR
message: Data from request object is passed to a new server-side request. This could
lead to a server-side request forgery (SSRF). To mitigate, ensure that schemes
and hosts are validated against an allowlist, do not forward the response to the
user, and ensure proper authentication and transport-layer security in the proxied
request.
metadata:
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
references:
- https://owasp.org/www-community/attacks/Server_Side_Request_Forgery
category: security
technology:
- flask
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/python.flask.security.injection.ssrf-requests.ssrf-requests
shortlink: https://sg.run/J9LW
semgrep.dev:
rule:
r_id: 9546
rv_id: 1263432
rule_id: WAUoRx
version_id: rxTAKJn
url: https://semgrep.dev/playground/r/rxTAKJn/python.flask.security.injection.ssrf-requests.ssrf-requests
origin: community
pattern-either:
- patterns:
- pattern: requests.$FUNC(...)
- pattern-either:
- pattern-inside: |
@$APP.$ROUTE_METHOD($ROUTE, ...)
def $ROUTE_FUNC(..., $ROUTEVAR, ...):
...
requests.$FUNC(..., <... $ROUTEVAR ...>, ...)
- pattern-inside: |
@$APP.$ROUTE_METHOD($ROUTE, ...)
def $ROUTE_FUNC(..., $ROUTEVAR, ...):
...
$INTERM = <... $ROUTEVAR ...>
...
requests.$FUNC(..., <... $INTERM ...>, ...)
- metavariable-regex:
metavariable: $ROUTE_METHOD
regex: ^(route|get|post|put|delete|patch)$
- pattern: requests.$FUNC(..., <... flask.request.$W.get(...) ...>, ...)
- pattern: requests.$FUNC(..., <... flask.request.$W[...] ...>, ...)
- pattern: requests.$FUNC(..., <... flask.request.$W(...) ...>, ...)
- pattern: requests.$FUNC(..., <... flask.request.$W ...>, ...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W.get(...) ...>
...
requests.$FUNC(<... $INTERM ...>, ...)
- pattern: requests.$FUNC(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W[...] ...>
...
requests.$FUNC(<... $INTERM ...>, ...)
- pattern: requests.$FUNC(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W(...) ...>
...
requests.$FUNC(<... $INTERM ...>, ...)
- pattern: requests.$FUNC(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W ...>
...
requests.$FUNC(<... $INTERM ...>, ...)
- pattern: requests.$FUNC(...)
- id: python.flask.security.injection.user-eval.eval-injection
languages:
- python
severity: ERROR
message: Detected user data flowing into eval. This is code injection and should
be avoided.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html
category: security
technology:
- flask
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.flask.security.injection.user-eval.eval-injection
shortlink: https://sg.run/5QpX
semgrep.dev:
rule:
r_id: 9547
rv_id: 1263436
rule_id: 0oU54W
version_id: w8TRoB0
url: https://semgrep.dev/playground/r/w8TRoB0/python.flask.security.injection.user-eval.eval-injection
origin: community
pattern-either:
- patterns:
- pattern: eval(...)
- pattern-either:
- pattern-inside: |
@$APP.route($ROUTE, ...)
def $FUNC(..., $ROUTEVAR, ...):
...
eval(..., <... $ROUTEVAR ...>, ...)
- pattern-inside: |
@$APP.route($ROUTE, ...)
def $FUNC(..., $ROUTEVAR, ...):
...
$INTERM = <... $ROUTEVAR ...>
...
eval(..., <... $INTERM ...>, ...)
- pattern: eval(..., <... flask.request.$W.get(...) ...>, ...)
- pattern: eval(..., <... flask.request.$W[...] ...>, ...)
- pattern: eval(..., <... flask.request.$W(...) ...>, ...)
- pattern: eval(..., <... flask.request.$W ...>, ...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W.get(...) ...>
...
eval(..., <... $INTERM ...>, ...)
- pattern: eval(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W[...] ...>
...
eval(..., <... $INTERM ...>, ...)
- pattern: eval(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W(...) ...>
...
eval(..., <... $INTERM ...>, ...)
- pattern: eval(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W ...>
...
eval(..., <... $INTERM ...>, ...)
- pattern: eval(...)
- id: python.flask.security.injection.user-exec.exec-injection
languages:
- python
severity: ERROR
message: Detected user data flowing into exec. This is code injection and should
be avoided.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://nedbatchelder.com/blog/201206/exec_really_is_dangerous.html
category: security
technology:
- flask
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.flask.security.injection.user-exec.exec-injection
shortlink: https://sg.run/Ge42
semgrep.dev:
rule:
r_id: 9548
rv_id: 1263437
rule_id: KxUbl2
version_id: xyTjzD9
url: https://semgrep.dev/playground/r/xyTjzD9/python.flask.security.injection.user-exec.exec-injection
origin: community
pattern-either:
- patterns:
- pattern: exec(...)
- pattern-either:
- pattern-inside: |
@$APP.route($ROUTE, ...)
def $FUNC(..., $ROUTEVAR, ...):
...
exec(..., <... $ROUTEVAR ...>, ...)
- pattern-inside: |
@$APP.route($ROUTE, ...)
def $FUNC(..., $ROUTEVAR, ...):
...
$INTERM = <... $ROUTEVAR ...>
...
exec(..., <... $INTERM ...>, ...)
- pattern: exec(..., <... flask.request.$W.get(...) ...>, ...)
- pattern: exec(..., <... flask.request.$W[...] ...>, ...)
- pattern: exec(..., <... flask.request.$W(...) ...>, ...)
- pattern: exec(..., <... flask.request.$W ...>, ...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W.get(...) ...>
...
exec(..., <... $INTERM ...>, ...)
- pattern: exec(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W[...] ...>
...
exec(..., <... $INTERM ...>, ...)
- pattern: exec(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W(...) ...>
...
exec(..., <... $INTERM ...>, ...)
- pattern: exec(...)
- patterns:
- pattern-inside: |
$INTERM = <... flask.request.$W ...>
...
exec(..., <... $INTERM ...>, ...)
- pattern: exec(...)
- id: python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret
message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently
Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html
Consider using an appropriate security mechanism to protect the credentials (e.g.
keeping secrets in environment variables)'
metadata:
cwe:
- 'CWE-522: Insufficiently Protected Credentials'
owasp:
- A02:2017 - Broken Authentication
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
references:
- https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
category: security
technology:
- jwt
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret
shortlink: https://sg.run/l2E9
semgrep.dev:
rule:
r_id: 9557
rv_id: 1263452
rule_id: X5U8P5
version_id: PkTR3X3
url: https://semgrep.dev/playground/r/PkTR3X3/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret
origin: community
patterns:
- pattern: |
jwt.encode($_, "...", ...)
languages:
- python
severity: ERROR
- id: python.jwt.security.jwt-none-alg.jwt-python-none-alg
message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm
assumes the integrity of the token has already been verified. This would allow
a malicious actor to forge a JWT token that will automatically be verified. Do
not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'.
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
category: security
technology:
- jwt
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.jwt.security.jwt-none-alg.jwt-python-none-alg
shortlink: https://sg.run/Yvp4
semgrep.dev:
rule:
r_id: 9558
rv_id: 1263453
rule_id: j2UvKw
version_id: JdTzxYj
url: https://semgrep.dev/playground/r/JdTzxYj/python.jwt.security.jwt-none-alg.jwt-python-none-alg
origin: community
languages:
- python
severity: ERROR
pattern-either:
- pattern: |
jwt.encode(...,algorithm="none",...)
- pattern: jwt.decode(...,algorithms=[...,"none",...],...)
- id: python.jwt.security.unverified-jwt-decode.unverified-jwt-decode
patterns:
- pattern-either:
- patterns:
- pattern: |
jwt.decode(..., options={..., "verify_signature": $BOOL, ...}, ...)
- metavariable-pattern:
metavariable: $BOOL
pattern: |
False
- focus-metavariable: $BOOL
- patterns:
- pattern: |
$OPTS = {..., "verify_signature": $BOOL, ...}
...
jwt.decode(..., options=$OPTS, ...)
- metavariable-pattern:
metavariable: $BOOL
pattern: |
False
- focus-metavariable: $BOOL
message: Detected JWT token decoded with 'verify=False'. This bypasses any integrity
checks for the token which means the token could be tampered with by malicious
actors. Ensure that the JWT token is verified.
metadata:
owasp:
- A02:2017 - Broken Authentication
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe:
- 'CWE-287: Improper Authentication'
references:
- https://github.com/we45/Vulnerable-Flask-App/blob/752ee16087c0bfb79073f68802d907569a1f0df7/app/app.py#L96
category: security
technology:
- jwt
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode
shortlink: https://sg.run/6nyB
semgrep.dev:
rule:
r_id: 9559
rv_id: 1263454
rule_id: 10UKjo
version_id: 5PTo12w
url: https://semgrep.dev/playground/r/5PTo12w/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode
origin: community
fix: |
True
severity: ERROR
languages:
- python
- id: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
pattern: hashlib.sha1(...)
fix-regex:
regex: sha1
replacement: sha256
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
collision resistant and is therefore not suitable as a cryptographic signature.
Use SHA256 or SHA3 instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B303
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.2 Insecure Custom Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
references:
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
- http://2012.sharcs.org/slides/stevens.pdf
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
category: security
technology:
- python
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
shortlink: https://sg.run/ydYx
semgrep.dev:
rule:
r_id: 9624
rv_id: 1263537
rule_id: x8UnBk
version_id: w8TRoE7
url: https://semgrep.dev/playground/r/w8TRoE7/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1
origin: community
severity: WARNING
languages:
- python
- id: python.lang.security.insecure-hash-function.insecure-hash-function
message: Detected use of an insecure MD4 or MD5 hash function. These functions have
known vulnerabilities and are considered deprecated. Consider using 'SHA256' or
a similar function instead.
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/hashlib_new_insecure_functions.py
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.2 Insecure Custom Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
references:
- https://tools.ietf.org/html/rfc6151
- https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
category: security
technology:
- python
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.lang.security.insecure-hash-function.insecure-hash-function
shortlink: https://sg.run/rdBn
semgrep.dev:
rule:
r_id: 9625
rv_id: 1263538
rule_id: OrU30g
version_id: xyTjzEe
url: https://semgrep.dev/playground/r/xyTjzEe/python.lang.security.insecure-hash-function.insecure-hash-function
origin: community
languages:
- python
severity: WARNING
pattern-either:
- pattern: hashlib.new("=~/[M|m][D|d][4|5]/", ...)
- pattern: hashlib.new(..., name="=~/[M|m][D|d][4|5]/", ...)
- id: python.lang.security.unverified-ssl-context.unverified-ssl-context
patterns:
- pattern-either:
- pattern: ssl._create_unverified_context(...)
- pattern: ssl._create_default_https_context = ssl._create_unverified_context
fix-regex:
regex: _create_unverified_context
replacement: create_default_context
message: Unverified SSL context detected. This will permit insecure connections
without verifying SSL certificates. Use 'ssl.create_default_context' instead.
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe:
- 'CWE-295: Improper Certificate Validation'
references:
- https://docs.python.org/3/library/ssl.html#ssl-security
- https://docs.python.org/3/library/http.client.html#http.client.HTTPSConnection
category: security
technology:
- python
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/python.lang.security.unverified-ssl-context.unverified-ssl-context
shortlink: https://sg.run/N4lp
semgrep.dev:
rule:
r_id: 9627
rv_id: 1263540
rule_id: v8UnkQ
version_id: e1Tyjlj
url: https://semgrep.dev/playground/r/e1Tyjlj/python.lang.security.unverified-ssl-context.unverified-ssl-context
origin: community
severity: ERROR
languages:
- python
- id: python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated
pattern: ssl.wrap_socket(...)
message: '''ssl.wrap_socket()'' is deprecated. This function creates an insecure
socket without server name indication or hostname matching. Instead, create an
SSL context using ''ssl.SSLContext()'' and use that to wrap a socket.'
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://docs.python.org/3/library/ssl.html#ssl.wrap_socket
- https://docs.python.org/3/library/ssl.html#ssl.SSLContext.wrap_socket
category: security
technology:
- python
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated
shortlink: https://sg.run/PJOY
semgrep.dev:
rule:
r_id: 9645
rv_id: 1263516
rule_id: BYUN2e
version_id: DkTRbgn
url: https://semgrep.dev/playground/r/DkTRbgn/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated
origin: community
languages:
- python
severity: WARNING
- id: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true
patterns:
- pattern: subprocess.$FUNC(..., shell=$TRUE, ...)
- metavariable-pattern:
metavariable: $TRUE
pattern: "True \n"
- pattern-not: subprocess.$FUNC("...", shell=True, ...)
- focus-metavariable: $TRUE
message: Found 'subprocess' function '$FUNC' with 'shell=True'. This is dangerous
because this call will spawn the command using a shell process. Doing so propagates
current shell settings and variables, which makes it much easier for a malicious
actor to execute commands. Use 'shell=False' instead.
fix: |
False
metadata:
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b602_subprocess_popen_with_shell_equals_true.html
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
references:
- https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess
- https://docs.python.org/3/library/subprocess.html
category: security
technology:
- python
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- secure default
likelihood: HIGH
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true
shortlink: https://sg.run/J92w
semgrep.dev:
rule:
r_id: 9646
rv_id: 1263518
rule_id: DbUpz2
version_id: 0bTKzDK
url: https://semgrep.dev/playground/r/0bTKzDK/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.audit.weak-ssl-version.weak-ssl-version
message: An insecure SSL version was detected. TLS versions 1.0, 1.1, and all SSL
versions are considered weak encryption and are deprecated. Use 'ssl.PROTOCOL_TLSv1_2'
or higher.
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/insecure_ssl_tls.py#L30
asvs:
section: V9 Communications Verification Requirements
control_id: 9.1.3 Weak TLS
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v91-client-communications-security-requirements
version: '4'
references:
- https://tools.ietf.org/html/rfc7568
- https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html
- https://docs.python.org/3/library/ssl.html#ssl.PROTOCOL_TLSv1_2
category: security
technology:
- python
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.lang.security.audit.weak-ssl-version.weak-ssl-version
shortlink: https://sg.run/RoZO
semgrep.dev:
rule:
r_id: 9649
rv_id: 1263520
rule_id: KxUbNG
version_id: qkTR7Ev
url: https://semgrep.dev/playground/r/qkTR7Ev/python.lang.security.audit.weak-ssl-version.weak-ssl-version
origin: community
languages:
- python
severity: WARNING
pattern-either:
- pattern: ssl.PROTOCOL_SSLv2
- pattern: ssl.PROTOCOL_SSLv3
- pattern: ssl.PROTOCOL_TLSv1
- pattern: ssl.PROTOCOL_TLSv1_1
- pattern: pyOpenSSL.SSL.SSLv2_METHOD
- pattern: pyOpenSSL.SSL.SSLv23_METHOD
- pattern: pyOpenSSL.SSL.SSLv3_METHOD
- pattern: pyOpenSSL.SSL.TLSv1_METHOD
- pattern: pyOpenSSL.SSL.TLSv1_1_METHOD
- id: python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context
options:
symbolic_propagation: true
mode: taint
pattern-sources:
- patterns:
- pattern: |
"$URL"
- metavariable-pattern:
metavariable: $URL
language: regex
patterns:
- pattern-regex: http://
- pattern-not-regex: .*://localhost
- pattern-not-regex: .*://127\.0\.0\.1
pattern-sinks:
- patterns:
- pattern-inside: |
with requests.Session(...) as $SESSION:
...
- pattern-either:
- pattern: $SESSION.$W($SINK, ...)
- pattern: $SESSION.request($METHOD, $SINK, ...)
- focus-metavariable: $SINK
fix-regex:
regex: '[Hh][Tt][Tt][Pp]://'
replacement: https://
count: 1
message: Detected a request using 'http://'. This request will be unencrypted. Use
'https://' instead.
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
asvs:
section: V9 Communications Verification Requirements
control_id: 9.2.1 Weak TLS
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements
version: '4'
category: security
technology:
- requests
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- audit
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context
shortlink: https://sg.run/Bk5W
semgrep.dev:
rule:
r_id: 9651
rv_id: 1263484
rule_id: lBU9BZ
version_id: vdT06wb
url: https://semgrep.dev/playground/r/vdT06wb/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context
origin: community
languages:
- python
severity: INFO
- id: python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http
options:
symbolic_propagation: true
mode: taint
pattern-sources:
- patterns:
- pattern: |
"$URL"
- metavariable-pattern:
metavariable: $URL
language: regex
patterns:
- pattern-regex: http://
- pattern-not-regex: .*://localhost
- pattern-not-regex: .*://127\.0\.0\.1
pattern-sinks:
- patterns:
- pattern-either:
- pattern: requests.Session(...).$W($SINK, ...)
- pattern: requests.Session(...).request($METHOD, $SINK, ...)
- focus-metavariable: $SINK
fix-regex:
regex: '[Hh][Tt][Tt][Pp]://'
replacement: https://
count: 1
message: Detected a request using 'http://'. This request will be unencrypted. Use
'https://' instead.
languages:
- python
severity: INFO
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
asvs:
section: V9 Communications Verification Requirements
control_id: 9.1.1 Weak TLS
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements
version: '4'
category: security
technology:
- requests
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- audit
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http
shortlink: https://sg.run/DoBY
semgrep.dev:
rule:
r_id: 9652
rv_id: 1263485
rule_id: YGURXw
version_id: d6Tyx02
url: https://semgrep.dev/playground/r/d6Tyx02/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http
origin: community
- id: python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http
fix-regex:
regex: '[Hh][Tt][Tt][Pp]://'
replacement: https://
count: 1
message: Detected a request using 'http://'. This request will be unencrypted, and
attackers could listen into traffic on the network and be able to obtain sensitive
information. Use 'https://' instead.
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
asvs:
section: V9 Communications Verification Requirements
control_id: 9.1.1 Weak TLS
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements
version: '4'
category: security
technology:
- requests
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- audit
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http
shortlink: https://sg.run/W8J4
semgrep.dev:
rule:
r_id: 9653
rv_id: 1263486
rule_id: 6JUjpG
version_id: ZRTKA9v
url: https://semgrep.dev/playground/r/ZRTKA9v/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http
origin: community
languages:
- python
severity: INFO
options:
symbolic_propagation: true
mode: taint
pattern-sources:
- patterns:
- pattern: |
"$URL"
- metavariable-pattern:
metavariable: $URL
language: regex
patterns:
- pattern-regex: http://
- pattern-not-regex: .*://localhost
- pattern-not-regex: .*://127\.0\.0\.1
pattern-sinks:
- patterns:
- pattern-either:
- pattern: requests.$W($SINK, ...)
- pattern: requests.request($METHOD, $SINK, ...)
- pattern: requests.Request($METHOD, $SINK, ...)
- focus-metavariable: $SINK
- id: python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure
patterns:
- pattern: |
$LOGGER_OBJ.$LOGGER_CALL($FORMAT_STRING,...)
- metavariable-regex:
metavariable: $LOGGER_OBJ
regex: (?i)(_logger|logger|self.logger|log)
- metavariable-regex:
metavariable: $LOGGER_CALL
regex: (debug|info|warn|warning|error|exception|critical)
- metavariable-regex:
metavariable: $FORMAT_STRING
regex: (?i).*(api.key|secret|credential|token|password).*\%s.*
message: Detected a python logger call with a potential hardcoded secret $FORMAT_STRING
being logged. This may lead to secret credentials being exposed. Make sure that
the logger is not logging sensitive information.
severity: WARNING
languages:
- python
metadata:
cwe:
- 'CWE-532: Insertion of Sensitive Information into Log File'
category: security
technology:
- python
owasp:
- A09:2021 - Security Logging and Monitoring Failures
- A09:2025 - Security Logging & Alerting Failures
references:
- https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure
shortlink: https://sg.run/ydNx
semgrep.dev:
rule:
r_id: 9668
rv_id: 1263501
rule_id: x8UnJk
version_id: A8TgdOR
url: https://semgrep.dev/playground/r/A8TgdOR/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure
origin: community
- id: python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces
message: Running `socket.bind` to 0.0.0.0, or empty string could unexpectedly expose
the server publicly as it binds to all available interfaces. Consider instead
getting correct address from an environment variable or configuration file.
metadata:
cwe:
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
category: security
technology:
- python
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces
shortlink: https://sg.run/rdln
semgrep.dev:
rule:
r_id: 9669
rv_id: 1263505
rule_id: OrU3og
version_id: 0bTKzDL
url: https://semgrep.dev/playground/r/0bTKzDL/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces
origin: community
languages:
- python
severity: INFO
pattern-either:
- pattern: |
$S = socket.socket(...)
...
$S.bind(("0.0.0.0", ...))
- pattern: |
$S = socket.socket(...)
...
$S.bind(("::", ...))
- pattern: |
$S = socket.socket(...)
...
$S.bind(("", ...))
- id: python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation
patterns:
- pattern-either:
- pattern: urllib3.PoolManager(..., cert_reqs=$REQS, ...)
- pattern: urllib3.ProxyManager(..., cert_reqs=$REQS, ...)
- pattern: urllib3.HTTPSConnectionPool(..., cert_reqs=$REQS, ...)
- pattern: urllib3.connectionpool.HTTPSConnectionPool(..., cert_reqs=$REQS, ...)
- pattern: urllib3.connection_from_url(..., cert_reqs=$REQS, ...)
- pattern: urllib3.proxy_from_url(..., cert_reqs=$REQS, ...)
- pattern: $CONTEXT.wrap_socket(..., cert_reqs=$REQS, ...)
- pattern: ssl.wrap_socket(..., cert_reqs=$REQS, ...)
- metavariable-regex:
metavariable: $REQS
regex: (NONE|CERT_NONE|CERT_OPTIONAL|ssl\.CERT_NONE|ssl\.CERT_OPTIONAL|\'NONE\'|\"NONE\"|\'OPTIONAL\'|\"OPTIONAL\")
message: certificate verification explicitly disabled, insecure connections possible
metadata:
cwe:
- 'CWE-295: Improper Certificate Validation'
owasp:
- A03:2017 - Sensitive Data Exposure
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
category: security
technology:
- python
references:
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation
shortlink: https://sg.run/b7yp
semgrep.dev:
rule:
r_id: 9670
rv_id: 1263506
rule_id: eqU87k
version_id: K3TKkZn
url: https://semgrep.dev/playground/r/K3TKkZn/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.audit.network.http-not-https-connection.http-not-https-connection
message: Detected HTTPConnectionPool. This will transmit data in cleartext. It is
recommended to use HTTPSConnectionPool instead for to encrypt communications.
metadata:
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://urllib3.readthedocs.io/en/1.2.1/pools.html#urllib3.connectionpool.HTTPSConnectionPool
category: security
technology:
- python
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection
shortlink: https://sg.run/N4Np
semgrep.dev:
rule:
r_id: 9671
rv_id: 1263507
rule_id: v8UnWQ
version_id: qkTR7E1
url: https://semgrep.dev/playground/r/qkTR7E1/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection
origin: community
languages:
- python
severity: ERROR
pattern-either:
- pattern: urllib3.HTTPConnectionPool(...)
- pattern: urllib3.connectionpool.HTTPConnectionPool(...)
- id: python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load
metadata:
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
references:
- https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation
- https://nvd.nist.gov/vuln/detail/CVE-2017-18342
category: security
technology:
- pyyaml
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load
shortlink: https://sg.run/we9Y
semgrep.dev:
rule:
r_id: 9673
rv_id: 1263530
rule_id: ZqU5jZ
version_id: 1QTyprw
url: https://semgrep.dev/playground/r/1QTyprw/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load
origin: community
languages:
- python
message: Detected a possible YAML deserialization vulnerability. `yaml.unsafe_load`,
`yaml.Loader`, `yaml.CLoader`, and `yaml.UnsafeLoader` are all known to be unsafe
methods of deserializing YAML. An attacker with control over the YAML input could
create special YAML input that allows the attacker to run arbitrary Python code.
This would allow the attacker to steal files, download and install malware, or
otherwise take over the machine. Use `yaml.safe_load` or `yaml.SafeLoader` instead.
fix-regex:
regex: unsafe_load
replacement: safe_load
count: 1
severity: ERROR
patterns:
- pattern-inside: |
import yaml
...
- pattern-not-inside: |
$YAML = ruamel.yaml.YAML(...)
...
- pattern-either:
- pattern: yaml.unsafe_load(...)
- pattern: yaml.load(..., Loader=yaml.Loader, ...)
- pattern: yaml.load(..., Loader=yaml.UnsafeLoader, ...)
- pattern: yaml.load(..., Loader=yaml.CLoader, ...)
- pattern: yaml.load_all(..., Loader=yaml.Loader, ...)
- pattern: yaml.load_all(..., Loader=yaml.UnsafeLoader, ...)
- pattern: yaml.load_all(..., Loader=yaml.CLoader, ...)
- id: python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel
metadata:
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
references:
- https://yaml.readthedocs.io/en/latest/basicuse.html?highlight=typ
category: security
technology:
- ruamel.yaml
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel
shortlink: https://sg.run/x1rz
semgrep.dev:
rule:
r_id: 9674
rv_id: 1263531
rule_id: nJUzqK
version_id: 9lT4bvG
url: https://semgrep.dev/playground/r/9lT4bvG/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel
origin: community
languages:
- python
message: Avoid using unsafe `ruamel.yaml.YAML()`. `ruamel.yaml.YAML` can create
arbitrary Python objects. A malicious actor could exploit this to run arbitrary
code. Use `YAML(typ='rt')` or `YAML(typ='safe')` instead.
severity: ERROR
pattern-either:
- pattern: ruamel.yaml.YAML(..., typ='unsafe', ...)
- pattern: ruamel.yaml.YAML(..., typ='base', ...)
- id: python.lang.security.deserialization.pickle.avoid-shelve
metadata:
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
references:
- https://docs.python.org/3/library/pickle.html
category: security
technology:
- python
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/python.lang.security.deserialization.pickle.avoid-shelve
shortlink: https://sg.run/dKkZ
semgrep.dev:
rule:
r_id: 9678
rv_id: 1263535
rule_id: 8GUje2
version_id: NdTzyb4
url: https://semgrep.dev/playground/r/NdTzyb4/python.lang.security.deserialization.pickle.avoid-shelve
origin: community
languages:
- python
message: Avoid using `shelve`, which uses `pickle`, which is known to lead to code
execution vulnerabilities. When unpickling, the serialized data could be manipulated
to run arbitrary code. Instead, consider serializing the relevant data as JSON
or a similar text-based serialization format.
severity: WARNING
pattern: shelve.$FUNC(...)
- id: python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor
message: Detected XOR cipher algorithm which is considered insecure. This algorithm
is not cryptographically secure and can be reversed easily. Use AES instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B304
references:
- https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption
category: security
technology:
- pycryptodome
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor
shortlink: https://sg.run/L0yr
semgrep.dev:
rule:
r_id: 9683
rv_id: 1263549
rule_id: PeUk5W
version_id: gETB7j3
url: https://semgrep.dev/playground/r/gETB7j3/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor
origin: community
severity: WARNING
languages:
- python
pattern-either:
- pattern: Cryptodome.Cipher.XOR.new(...)
- pattern: Crypto.Cipher.XOR.new(...)
- id: python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
collision resistant and is therefore not suitable as a cryptographic signature.
Use SHA256 or SHA3 instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
- http://2012.sharcs.org/slides/stevens.pdf
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
category: security
technology:
- pycryptodome
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1
shortlink: https://sg.run/3ALr
semgrep.dev:
rule:
r_id: 9687
rv_id: 1263553
rule_id: ReUPO3
version_id: PkTR3vk
url: https://semgrep.dev/playground/r/PkTR3vk/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1
origin: community
severity: WARNING
languages:
- python
pattern-either:
- pattern: Crypto.Hash.SHA.new(...)
- pattern: Cryptodome.Hash.SHA.new (...)
- id: python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size
message: Detected an insufficient key size for DSA. NIST recommends a key size of
2048 or higher.
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
references:
- https://www.pycryptodome.org/src/public_key/dsa
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf
category: security
technology:
- pycryptodome
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
functional-categories:
- crypto::search::key-length::pycryptodome
- crypto::search::key-length::pycryptodomex
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size
shortlink: https://sg.run/4y8l
semgrep.dev:
rule:
r_id: 9688
rv_id: 1263554
rule_id: AbUWje
version_id: JdTzxbQ
url: https://semgrep.dev/playground/r/JdTzxbQ/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size
origin: community
options:
symbolic_propagation: true
languages:
- python
severity: WARNING
patterns:
- pattern-either:
- pattern: Crypto.PublicKey.DSA.generate(..., bits=$SIZE, ...)
- pattern: Crypto.PublicKey.DSA.generate($SIZE, ...)
- pattern: Cryptodome.PublicKey.DSA.generate(..., bits=$SIZE, ...)
- pattern: Cryptodome.PublicKey.DSA.generate($SIZE, ...)
- metavariable-comparison:
metavariable: $SIZE
comparison: $SIZE < 2048
- id: python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size
message: Detected an insufficient key size for RSA. NIST recommends a key size of
3072 or higher.
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py
references:
- https://www.pycryptodome.org/src/public_key/rsa#rsa
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf
category: security
technology:
- pycryptodome
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
functional-categories:
- crypto::search::key-length::pycryptodome
- crypto::search::key-length::pycryptodomex
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size
shortlink: https://sg.run/PprY
semgrep.dev:
rule:
r_id: 9689
rv_id: 1263555
rule_id: BYUBWe
version_id: 5PTo1jL
url: https://semgrep.dev/playground/r/5PTo1jL/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size
origin: community
options:
symbolic_propagation: true
languages:
- python
severity: WARNING
patterns:
- pattern-either:
- pattern: Crypto.PublicKey.RSA.generate(..., bits=$SIZE, ...)
- pattern: Crypto.PublicKey.RSA.generate($SIZE, ...)
- pattern: Cryptodome.PublicKey.RSA.generate(..., bits=$SIZE, ...)
- pattern: Cryptodome.PublicKey.RSA.generate($SIZE, ...)
- metavariable-comparison:
metavariable: $SIZE
comparison: $SIZE < 3072
- id: python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection
patterns:
- pattern-either:
- pattern: |
def $FUNC(...,$VAR,...):
...
$SESSION.query(...).$SQLFUNC("...".$FORMATFUNC(...,$VAR,...))
- pattern: |
def $FUNC(...,$VAR,...):
...
$SESSION.query.join(...).$SQLFUNC("...".$FORMATFUNC(...,$VAR,...))
- pattern: |
def $FUNC(...,$VAR,...):
...
$SESSION.query.$SQLFUNC("...".$FORMATFUNC(...,$VAR,...))
- pattern: |
def $FUNC(...,$VAR,...):
...
query.$SQLFUNC("...".$FORMATFUNC(...,$VAR,...))
- metavariable-regex:
metavariable: $SQLFUNC
regex: (group_by|order_by|distinct|having|filter)
- metavariable-regex:
metavariable: $FORMATFUNC
regex: (?!bindparams)
message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause
sql injections if the developer inputs raw SQL into the before-mentioned clauses.
This pattern captures relevant cases in which the developer inputs raw SQL into
the distinct, having, group_by, order_by or filter clauses and injects user-input
into the raw SQL with any function besides "bindparams". Use bindParams to securely
bind user-input to SQL statements.
fix-regex:
regex: format
replacement: bindparams
languages:
- python
severity: WARNING
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
category: security
technology:
- sqlalchemy
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection
shortlink: https://sg.run/J3Xo
semgrep.dev:
rule:
r_id: 9702
rv_id: 1263579
rule_id: BYUBWo
version_id: NdTzyL4
url: https://semgrep.dev/playground/r/NdTzyL4/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection
origin: community
- id: ruby.lang.security.bad-deserialization.bad-deserialization
mode: taint
pattern-sources:
- pattern-either:
- pattern: params
- pattern: cookies
pattern-sinks:
- pattern-either:
- pattern: |
CSV.load(...)
- pattern: |
Marshal.load(...)
- pattern: |
Marshal.restore(...)
- pattern: |
Oj.object_load(...)
- pattern: |
Oj.load($X)
message: Checks for unsafe deserialization. Objects in Ruby can be serialized into
strings, then later loaded from strings. However, uses of load and object_load
can cause remote code execution. Loading user input with MARSHAL or CSV can potentially
be dangerous. Use JSON in a secure fashion instead.
metadata:
references:
- https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ
- https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb
category: security
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
technology:
- ruby
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/ruby.lang.security.bad-deserialization.bad-deserialization
shortlink: https://sg.run/DJj2
semgrep.dev:
rule:
r_id: 9708
rv_id: 1263595
rule_id: lBUdQg
version_id: 3ZT4Xqp
url: https://semgrep.dev/playground/r/3ZT4Xqp/ruby.lang.security.bad-deserialization.bad-deserialization
origin: community
languages:
- ruby
severity: ERROR
- id: ruby.lang.security.force-ssl-false.force-ssl-false
message: Checks for configuration setting of force_ssl to false. Force_ssl forces
usage of HTTPS, which could lead to network interception of unencrypted application
traffic. To fix, set config.force_ssl = true.
metadata:
cwe:
- 'CWE-311: Missing Encryption of Sensitive Data'
references:
- https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_force_ssl.rb
category: security
technology:
- ruby
owasp:
- A03:2017 - Sensitive Data Exposure
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/ruby.lang.security.force-ssl-false.force-ssl-false
shortlink: https://sg.run/YgkW
semgrep.dev:
rule:
r_id: 9714
rv_id: 1263605
rule_id: 2ZU4lx
version_id: WrTqKB3
url: https://semgrep.dev/playground/r/WrTqKB3/ruby.lang.security.force-ssl-false.force-ssl-false
origin: community
languages:
- ruby
severity: WARNING
pattern: config.force_ssl = false
fix-regex:
regex: =\s*false
replacement: = true
- id: ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller
patterns:
- pattern-inside: |
class $CONTROLLER < ApplicationController
...
http_basic_authenticate_with ..., :password => "$SECRET", ...
end
- focus-metavariable: $SECRET
message: Detected hardcoded password used in basic authentication in a controller
class. Including this password in version control could expose this credential.
Consider refactoring to use environment variables or configuration files.
severity: WARNING
metadata:
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/basic_auth/index.markdown
category: security
technology:
- ruby
- secrets
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller
shortlink: https://sg.run/6r0w
semgrep.dev:
rule:
r_id: 9715
rv_id: 1263606
rule_id: X5UZWK
version_id: 0bTKzNK
url: https://semgrep.dev/playground/r/0bTKzNK/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller
origin: community
languages:
- ruby
- id: ruby.lang.security.no-eval.ruby-eval
message: Use of eval with user-controllable input detected. This can lead to attackers
running arbitrary code. Ensure external data does not reach here, otherwise this
is a security vulnerability. Consider other ways to do this without eval.
severity: WARNING
metadata:
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
category: security
cwe2022-top25: true
cwe2021-top25: true
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_evaluation.rb
subcategory:
- vuln
technology:
- ruby
- rails
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/ruby.lang.security.no-eval.ruby-eval
shortlink: https://sg.run/bDwZ
semgrep.dev:
rule:
r_id: 9726
rv_id: 1263615
rule_id: OrUGNk
version_id: A8TgdDv
url: https://semgrep.dev/playground/r/A8TgdDv/ruby.lang.security.no-eval.ruby-eval
origin: community
languages:
- ruby
mode: taint
pattern-sources:
- pattern-either:
- pattern: params
- pattern: cookies
- patterns:
- pattern: |
RubyVM::InstructionSequence.compile(...)
- pattern-not: |
RubyVM::InstructionSequence.compile("...")
pattern-sinks:
- patterns:
- pattern-either:
- pattern: $X.eval
- pattern: $X.class_eval
- pattern: $X.instance_eval
- pattern: $X.module_eval
- pattern: $X.eval(...)
- pattern: $X.class_eval(...)
- pattern: $X.instance_eval(...)
- pattern: $X.module_eval(...)
- pattern: eval(...)
- pattern: class_eval(...)
- pattern: module_eval(...)
- pattern: instance_eval(...)
- pattern-not: $M("...",...)
- id: ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify
pattern: OpenSSL::SSL::VERIFY_NONE
message: Detected SSL that will accept an unverified connection. This makes the
connections susceptible to man-in-the-middle attacks. Use 'OpenSSL::SSL::VERIFY_PEER'
instead.
fix-regex:
regex: VERIFY_NONE
replacement: VERIFY_PEER
severity: WARNING
languages:
- ruby
metadata:
cwe:
- 'CWE-295: Improper Certificate Validation'
category: security
technology:
- ruby
owasp:
- A03:2017 - Sensitive Data Exposure
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
references:
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify
shortlink: https://sg.run/kLxX
semgrep.dev:
rule:
r_id: 9728
rv_id: 1263617
rule_id: v8U5Yn
version_id: DkTRbl4
url: https://semgrep.dev/playground/r/DkTRbl4/ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify
origin: community
- id: ruby.lang.security.weak-hashes-md5.weak-hashes-md5
message: Should not use md5 to generate hashes. md5 is proven to be vulnerable through
the use of brute-force attacks. Could also result in collisions, leading to potential
collision attacks. Use SHA256 or other hashing functions instead.
metadata:
cwe:
- 'CWE-328: Use of Weak Hash'
references:
- https://www.ibm.com/support/pages/security-bulletin-vulnerability-md5-signature-and-hash-algorithm-affects-sterling-integrator-and-sterling-file-gateway-cve-2015-7575
category: security
technology:
- ruby
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/ruby.lang.security.weak-hashes-md5.weak-hashes-md5
shortlink: https://sg.run/O1re
semgrep.dev:
rule:
r_id: 9731
rv_id: 1263619
rule_id: nJUYxZ
version_id: 0bTKzN8
url: https://semgrep.dev/playground/r/0bTKzN8/ruby.lang.security.weak-hashes-md5.weak-hashes-md5
origin: community
languages:
- ruby
severity: WARNING
pattern-either:
- pattern: Digest::MD5.base64digest $X
- pattern: Digest::MD5.hexdigest $X
- pattern: Digest::MD5.digest $X
- pattern: Digest::MD5.new
- pattern: OpenSSL::Digest::MD5.base64digest $X
- pattern: OpenSSL::Digest::MD5.hexdigest $X
- pattern: OpenSSL::Digest::MD5.digest $X
- pattern: OpenSSL::Digest::MD5.new
- id: ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1
message: Should not use SHA1 to generate hashes. There is a proven SHA1 hash collision
by Google, which could lead to vulnerabilities. Use SHA256, SHA3 or other hashing
functions instead.
metadata:
cwe:
- 'CWE-328: Use of Weak Hash'
references:
- https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html
- https://shattered.io/
category: security
technology:
- ruby
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1
shortlink: https://sg.run/e4qX
semgrep.dev:
rule:
r_id: 9732
rv_id: 1263620
rule_id: EwU4jq
version_id: K3TKkEZ
url: https://semgrep.dev/playground/r/K3TKkEZ/ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1
origin: community
languages:
- ruby
severity: WARNING
pattern-either:
- pattern: Digest::SHA1.$FUNC
- pattern: OpenSSL::Digest::SHA1.$FUNC
- pattern: OpenSSL::HMAC.$FUNC("sha1",...)
- id: terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket
pattern: acl = "public-read-write"
languages:
- hcl
severity: ERROR
message: S3 bucket with public read-write access detected.
metadata:
references:
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#acl
- https://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html#canned-acl
cwe:
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
category: security
technology:
- terraform
- aws
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket
shortlink: https://sg.run/0nok
semgrep.dev:
rule:
r_id: 9754
rv_id: 1263900
rule_id: 6JUqvn
version_id: PkTR3y5
url: https://semgrep.dev/playground/r/PkTR3y5/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket
origin: community
- id: typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust
message: Detected the use of `$TRUST`. This can introduce a Cross-Site-Scripting
(XSS) vulnerability if this comes from user-provided input. If you have to use
`$TRUST`, ensure it does not come from user-input or use the appropriate prevention
mechanism e.g. input validation or sanitization depending on the context.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
references:
- https://angular.io/api/platform-browser/DomSanitizer
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
confidence: MEDIUM
category: security
technology:
- angular
- browser
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust
shortlink: https://sg.run/KWxP
semgrep.dev:
rule:
r_id: 9755
rv_id: 1263902
rule_id: oqUzgA
version_id: 5PTo1zk
url: https://semgrep.dev/playground/r/5PTo1zk/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust
origin: community
languages:
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
function ...({..., $X: string, ...}) { ... }
- pattern-inside: |
function ...(..., $X: string, ...) { ... }
- focus-metavariable: $X
pattern-sinks:
- patterns:
- pattern-either:
- pattern: $X.$TRUST($Y)
- focus-metavariable: $Y
- pattern-not: |
$X.$TRUST(`...`)
- pattern-not: |
$X.$TRUST("...")
- metavariable-regex:
metavariable: $TRUST
regex: (bypassSecurityTrustHtml|bypassSecurityTrustStyle|bypassSecurityTrustScript|bypassSecurityTrustUrl|bypassSecurityTrustResourceUrl)
pattern-sanitizers:
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
import * as $S from "underscore.string"
...
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
$S = require("underscore.string")
...
- pattern-either:
- pattern: $S.escapeHTML(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "dompurify"
...
- pattern-inside: |
import { ..., $S,... } from "dompurify"
...
- pattern-inside: |
import * as $S from "dompurify"
...
- pattern-inside: |
$S = require("dompurify")
...
- pattern-inside: |
import $S from "isomorphic-dompurify"
...
- pattern-inside: |
import * as $S from "isomorphic-dompurify"
...
- pattern-inside: |
$S = require("isomorphic-dompurify")
...
- pattern-either:
- patterns:
- pattern-inside: |
$VALUE = $S(...)
...
- pattern: $VALUE.sanitize(...)
- patterns:
- pattern-inside: |
$VALUE = $S.sanitize
...
- pattern: $S(...)
- pattern: $S.sanitize(...)
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'xss';
...
- pattern-inside: |
import * as $S from 'xss';
...
- pattern-inside: |
$S = require("xss")
...
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'sanitize-html';
...
- pattern-inside: |
import * as $S from "sanitize-html";
...
- pattern-inside: |
$S = require("sanitize-html")
...
- pattern: $S(...)
- patterns:
- pattern: sanitizer.sanitize(...)
- pattern-not: sanitizer.sanitize(SecurityContext.NONE, ...);
- id: typescript.react.security.react-insecure-request.react-insecure-request
message: Unencrypted request over HTTP detected.
metadata:
vulnerability: Insecure Transport
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
references:
- https://www.npmjs.com/package/axios
category: security
technology:
- react
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/typescript.react.security.react-insecure-request.react-insecure-request
shortlink: https://sg.run/1n0b
semgrep.dev:
rule:
r_id: 9766
rv_id: 1263918
rule_id: NbUA3O
version_id: A8Tgd2p
url: https://semgrep.dev/playground/r/A8Tgd2p/typescript.react.security.react-insecure-request.react-insecure-request
origin: community
languages:
- typescript
- javascript
severity: ERROR
patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern-inside: |
import $AXIOS from 'axios';
...
$AXIOS.$METHOD(...)
- pattern-inside: |
$AXIOS = require('axios');
...
$AXIOS.$METHOD(...)
- pattern: $AXIOS.$VERB("$URL",...)
- metavariable-regex:
metavariable: $VERB
regex: ^(get|post|delete|head|patch|put|options)
- patterns:
- pattern-either:
- pattern-inside: |
import $AXIOS from 'axios';
...
$AXIOS(...)
- pattern-inside: |
$AXIOS = require('axios');
...
$AXIOS(...)
- pattern-either:
- pattern: '$AXIOS({url: "$URL"}, ...)'
- pattern: |
$OPTS = {url: "$URL"}
...
$AXIOS($OPTS, ...)
- pattern: fetch("$URL", ...)
- metavariable-regex:
metavariable: $URL
regex: ^([Hh][Tt][Tt][Pp]:\/\/(?!localhost).*)
- id: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml
message: Detection of dangerouslySetInnerHTML from non-constant definition. This
can inadvertently expose users to cross-site scripting (XSS) attacks if this comes
from user-provided input. If you have to use dangerouslySetInnerHTML, consider
using a sanitization library such as DOMPurify to sanitize your HTML.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html
category: security
confidence: MEDIUM
technology:
- react
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml
shortlink: https://sg.run/rAx6
semgrep.dev:
rule:
r_id: 9769
rv_id: 1263912
rule_id: x8UWvK
version_id: l4TJR0v
url: https://semgrep.dev/playground/r/l4TJR0v/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml
origin: community
languages:
- typescript
- javascript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
function ...({..., $X, ...}) { ... }
- pattern-inside: |
function ...(..., $X, ...) { ... }
- focus-metavariable: $X
- pattern-not-inside: |
$F. ... .$SANITIZEUNC(...)
pattern-sinks:
- patterns:
- focus-metavariable: $X
- pattern-either:
- pattern: |
{...,dangerouslySetInnerHTML: {__html: $X},...}
- pattern: |
<$Y ... dangerouslySetInnerHTML={{__html: $X}} />
- pattern-not: |
<$Y ... dangerouslySetInnerHTML={{__html: "..."}} />
- pattern-not: |
{...,dangerouslySetInnerHTML:{__html: "..."},...}
- metavariable-pattern:
patterns:
- pattern-not: |
{...}
metavariable: $X
- pattern-not: |
<... {__html: "..."} ...>
- pattern-not: |
<... {__html: `...`} ...>
pattern-sanitizers:
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
import * as $S from "underscore.string"
...
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
$S = require("underscore.string")
...
- pattern-either:
- pattern: $S.escapeHTML(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "dompurify"
...
- pattern-inside: |
import { ..., $S,... } from "dompurify"
...
- pattern-inside: |
import * as $S from "dompurify"
...
- pattern-inside: |
$S = require("dompurify")
...
- pattern-inside: |
import $S from "isomorphic-dompurify"
...
- pattern-inside: |
import * as $S from "isomorphic-dompurify"
...
- pattern-inside: |
$S = require("isomorphic-dompurify")
...
- pattern-either:
- patterns:
- pattern-inside: |
$VALUE = $S(...)
...
- pattern: $VALUE.sanitize(...)
- patterns:
- pattern-inside: |
$VALUE = $S.sanitize
...
- pattern: $S(...)
- pattern: $S.sanitize(...)
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'xss';
...
- pattern-inside: |
import * as $S from 'xss';
...
- pattern-inside: |
$S = require("xss")
...
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'sanitize-html';
...
- pattern-inside: |
import * as $S from "sanitize-html";
...
- pattern-inside: |
$S = require("sanitize-html")
...
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
$S = new Remarkable()
...
- pattern: $S.render(...)
- id: typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method
message: Detection of $HTML from non-constant definition. This can inadvertently
expose users to cross-site scripting (XSS) attacks if this comes from user-provided
input. If you have to use $HTML, consider using a sanitization library such as
DOMPurify to sanitize your HTML.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://developer.mozilla.org/en-US/docs/Web/API/Document/writeln
- https://developer.mozilla.org/en-US/docs/Web/API/Document/write
- https://developer.mozilla.org/en-US/docs/Web/API/Element/insertAdjacentHTML
category: security
confidence: MEDIUM
technology:
- react
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method
shortlink: https://sg.run/E5x8
semgrep.dev:
rule:
r_id: 9781
rv_id: 1263916
rule_id: QrU68w
version_id: GxTkeRl
url: https://semgrep.dev/playground/r/GxTkeRl/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method
origin: community
languages:
- typescript
- javascript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
function ...({..., $X, ...}) { ... }
- pattern-inside: |
function ...(..., $X, ...) { ... }
- focus-metavariable: $X
- pattern-either:
- pattern: $X.$Y
- pattern: $X[...]
pattern-sinks:
- patterns:
- pattern-either:
- pattern: "this.window.document. ... .$HTML('...',$SINK) \n"
- pattern: "window.document. ... .$HTML('...',$SINK) \n"
- pattern: "document.$HTML($SINK) \n"
- metavariable-regex:
metavariable: $HTML
regex: (writeln|write)
- focus-metavariable: $SINK
- patterns:
- pattern-either:
- pattern: "$PROP. ... .$HTML('...',$SINK) \n"
- metavariable-regex:
metavariable: $HTML
regex: (insertAdjacentHTML)
- focus-metavariable: $SINK
pattern-sanitizers:
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
import * as $S from "underscore.string"
...
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
$S = require("underscore.string")
...
- pattern-either:
- pattern: $S.escapeHTML(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "dompurify"
...
- pattern-inside: |
import { ..., $S,... } from "dompurify"
...
- pattern-inside: |
import * as $S from "dompurify"
...
- pattern-inside: |
$S = require("dompurify")
...
- pattern-inside: |
import $S from "isomorphic-dompurify"
...
- pattern-inside: |
import * as $S from "isomorphic-dompurify"
...
- pattern-inside: |
$S = require("isomorphic-dompurify")
...
- pattern-either:
- patterns:
- pattern-inside: |
$VALUE = $S(...)
...
- pattern: $VALUE.sanitize(...)
- patterns:
- pattern-inside: |
$VALUE = $S.sanitize
...
- pattern: $S(...)
- pattern: $S.sanitize(...)
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'xss';
...
- pattern-inside: |
import * as $S from 'xss';
...
- pattern-inside: |
$S = require("xss")
...
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'sanitize-html';
...
- pattern-inside: |
import * as $S from "sanitize-html";
...
- pattern-inside: |
$S = require("sanitize-html")
...
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
$S = new Remarkable()
...
- pattern: $S.render(...)
- id: typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property
message: Detection of $HTML from non-constant definition. This can inadvertently
expose users to cross-site scripting (XSS) attacks if this comes from user-provided
input. If you have to use $HTML, consider using a sanitization library such as
DOMPurify to sanitize your HTML.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html
category: security
confidence: MEDIUM
technology:
- react
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property
shortlink: https://sg.run/70Zv
semgrep.dev:
rule:
r_id: 9782
rv_id: 1263917
rule_id: 3qUBl4
version_id: RGT0Lln
url: https://semgrep.dev/playground/r/RGT0Lln/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property
origin: community
languages:
- typescript
- javascript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
function ...({..., $X, ...}) { ... }
- pattern-inside: |
function ...(..., $X, ...) { ... }
- focus-metavariable: $X
- pattern-either:
- pattern: $X.$Y
- pattern: $X[...]
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
$BODY = $REACT.useRef(...)
...
- pattern-inside: |
$BODY = useRef(...)
...
- pattern-inside: |
$BODY = findDOMNode(...)
...
- pattern-inside: |
$BODY = createRef(...)
...
- pattern-inside: |
$BODY = $REACT.findDOMNode(...)
...
- pattern-inside: |
$BODY = $REACT.createRef(...)
...
- pattern-either:
- pattern: "$BODY. ... .$HTML = $SINK \n"
- pattern: "$BODY.$HTML = $SINK \n"
- metavariable-regex:
metavariable: $HTML
regex: (innerHTML|outerHTML)
- focus-metavariable: $SINK
- patterns:
- pattern-either:
- pattern: ReactDOM.findDOMNode(...).$HTML = $SINK
- metavariable-regex:
metavariable: $HTML
regex: (innerHTML|outerHTML)
- focus-metavariable: $SINK
pattern-sanitizers:
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
import * as $S from "underscore.string"
...
- pattern-inside: |
import $S from "underscore.string"
...
- pattern-inside: |
$S = require("underscore.string")
...
- pattern-either:
- pattern: $S.escapeHTML(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from "dompurify"
...
- pattern-inside: |
import { ..., $S,... } from "dompurify"
...
- pattern-inside: |
import * as $S from "dompurify"
...
- pattern-inside: |
$S = require("dompurify")
...
- pattern-inside: |
import $S from "isomorphic-dompurify"
...
- pattern-inside: |
import * as $S from "isomorphic-dompurify"
...
- pattern-inside: |
$S = require("isomorphic-dompurify")
...
- pattern-either:
- patterns:
- pattern-inside: |
$VALUE = $S(...)
...
- pattern: $VALUE.sanitize(...)
- patterns:
- pattern-inside: |
$VALUE = $S.sanitize
...
- pattern: $S(...)
- pattern: $S.sanitize(...)
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'xss';
...
- pattern-inside: |
import * as $S from 'xss';
...
- pattern-inside: |
$S = require("xss")
...
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
import $S from 'sanitize-html';
...
- pattern-inside: |
import * as $S from "sanitize-html";
...
- pattern-inside: |
$S = require("sanitize-html")
...
- pattern: $S(...)
- patterns:
- pattern-either:
- pattern-inside: |
$S = new Remarkable()
...
- pattern: $S.render(...)
- id: ruby.lang.security.dangerous-exec.dangerous-exec
mode: taint
pattern-sources:
- patterns:
- pattern: |
def $F(...,$ARG,...)
...
end
- focus-metavariable: $ARG
- pattern: params
- pattern: cookies
pattern-sinks:
- patterns:
- pattern: |
$EXEC(...)
- pattern-not: |
$EXEC("...","...","...",...)
- pattern-not: |
$EXEC(["...","...","...",...],...)
- pattern-not: |
$EXEC({...},"...","...","...",...)
- pattern-not: |
$EXEC({...},["...","...","...",...],...)
- metavariable-regex:
metavariable: $EXEC
regex: ^(system|exec|spawn|Process.exec|Process.spawn|Open3.capture2|Open3.capture2e|Open3.capture3|Open3.popen2|Open3.popen2e|Open3.popen3|IO.popen|Gem::Util.popen|PTY.spawn)$
message: Detected non-static command inside $EXEC. Audit the input to '$EXEC'. If
unverified user data can reach this call site, this is a code injection vulnerability.
A malicious actor can inject a malicious script to execute arbitrary code.
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_execute.rb
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- ruby
- rails
references:
- https://guides.rubyonrails.org/security.html#command-line-injection
cwe2022-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/ruby.lang.security.dangerous-exec.dangerous-exec
shortlink: https://sg.run/R8GY
semgrep.dev:
rule:
r_id: 9805
rv_id: 1409405
rule_id: WAUZOw
version_id: WrT7erb
url: https://semgrep.dev/playground/r/WrT7erb/ruby.lang.security.dangerous-exec.dangerous-exec
origin: community
severity: WARNING
languages:
- ruby
- id: javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run
message: Detected non-literal calls to Deno.run(). This could lead to a command
injection vulnerability.
metadata:
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- deno
references:
- https://deno.land/manual/examples/subprocess#simple-example
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run
shortlink: https://sg.run/Nrrn
semgrep.dev:
rule:
r_id: 9927
rv_id: 1409397
rule_id: x8UWWg
version_id: PkTe7AP
url: https://semgrep.dev/playground/r/PkTe7AP/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-inside: function ... (..., $ARG,...) {...}
- focus-metavariable: $ARG
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
Deno.run({cmd: [$INPUT,...]},...)
- pattern: |
Deno.run({cmd: ["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$INPUT,...]},...)
- patterns:
- pattern: |
Deno.run({cmd: [$CMD,"-c",$INPUT,...]},...)
- pattern-inside: |
$CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/"
...
- focus-metavariable: $INPUT
- id: yaml.docker-compose.security.privileged-service.privileged-service
patterns:
- pattern-inside: |
version: ...
...
services:
...
$SERVICE:
...
privileged: $TRUE
- focus-metavariable: $TRUE
- metavariable-regex:
metavariable: $TRUE
regex: (true)
fix: |
false
message: Service '$SERVICE' is running in privileged mode. This grants the container
the equivalent of root capabilities on the host machine. This can lead to container
escapes, privilege escalation, and other security concerns. Remove the 'privileged'
key to disable this capability.
metadata:
cwe:
- 'CWE-250: Execution with Unnecessary Privileges'
owasp:
- A06:2017 - Security Misconfiguration
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://www.trendmicro.com/en_us/research/19/l/why-running-a-privileged-container-in-docker-is-a-bad-idea.html
- https://containerjournal.com/topics/container-security/why-running-a-privileged-container-is-not-a-good-idea/
category: security
technology:
- docker-compose
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/yaml.docker-compose.security.privileged-service.privileged-service
shortlink: https://sg.run/AlX0
semgrep.dev:
rule:
r_id: 10006
rv_id: 1263922
rule_id: DbUW17
version_id: 0bTKzXZ
url: https://semgrep.dev/playground/r/0bTKzXZ/yaml.docker-compose.security.privileged-service.privileged-service
origin: community
languages:
- yaml
severity: WARNING
- id: yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation
patterns:
- pattern-inside: |
containers:
...
- pattern-inside: |
- name: $CONTAINER
...
- pattern: |
image: ...
...
- pattern-inside: |
image: ...
...
$SC:
...
- metavariable-regex:
metavariable: $SC
regex: ^(securityContext)$
- pattern-not-inside: |
image: ...
...
securityContext:
...
allowPrivilegeEscalation: $VAL
- focus-metavariable: $SC
fix: |
securityContext:
allowPrivilegeEscalation: false #
message: In Kubernetes, each pod runs in its own isolated environment with its own
set of security policies. However, certain container images may contain `setuid`
or `setgid` binaries that could allow an attacker to perform privilege escalation
and gain access to sensitive resources. To mitigate this risk, it's recommended
to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation`
set to `false`. This will prevent the container from running any privileged processes
and limit the impact of any potential attacks. By adding the `allowPrivilegeEscalation`
parameter to your the `securityContext`, you can help to ensure that your containerized
applications are more secure and less vulnerable to privilege escalation attacks.
metadata:
cwe:
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
owasp:
- A05:2021 - Security Misconfiguration
- A06:2017 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation
- https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
- https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt
- https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag
category: security
technology:
- kubernetes
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation
shortlink: https://sg.run/ljp6
semgrep.dev:
rule:
r_id: 10057
rv_id: 1263933
rule_id: 6JUqEO
version_id: jQTn527
url: https://semgrep.dev/playground/r/jQTn527/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation
origin: community
languages:
- yaml
severity: WARNING
- id: yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled
patterns:
- pattern-inside: |
containers:
...
- pattern: |
image: ...
...
securityContext:
...
seccompProfile: unconfined
message: 'Container is explicitly disabling seccomp confinement. This runs the service
in an unrestricted state. Remove ''seccompProfile: unconfined'' to prevent this.'
metadata:
cwe:
- 'CWE-284: Improper Access Control'
references:
- https://kubernetes.io/docs/concepts/policy/pod-security-policy/#seccomp
- https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
category: security
technology:
- kubernetes
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled
shortlink: https://sg.run/6rgY
semgrep.dev:
rule:
r_id: 10059
rv_id: 1263941
rule_id: zdUynw
version_id: w8TRoL3
url: https://semgrep.dev/playground/r/w8TRoL3/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled
origin: community
languages:
- yaml
severity: WARNING
- id: yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster
pattern: |
cluster:
...
insecure-skip-tls-verify: true
message: 'Cluster is disabling TLS certificate verification when communicating with
the server. This makes your HTTPS connections insecure. Remove the ''insecure-skip-tls-verify:
true'' key to secure communication.'
metadata:
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
references:
- https://kubernetes.io/docs/reference/config-api/client-authentication.v1beta1/#client-authentication-k8s-io-v1beta1-Cluster
category: security
technology:
- kubernetes
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster
shortlink: https://sg.run/okyn
semgrep.dev:
rule:
r_id: 10116
rv_id: 1263943
rule_id: zdUyWx
version_id: O9Tpxbo
url: https://semgrep.dev/playground/r/O9Tpxbo/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster
origin: community
languages:
- yaml
severity: WARNING
- id: yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service
pattern: |
spec:
...
insecureSkipTLSVerify: true
message: 'Service is disabling TLS certificate verification when communicating with
the server. This makes your HTTPS connections insecure. Remove the ''insecureSkipTLSVerify:
true'' key to secure communication.'
metadata:
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
references:
- https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#apiservice-v1-apiregistration-k8s-io
category: security
technology:
- kubernetes
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service
shortlink: https://sg.run/zk10
semgrep.dev:
rule:
r_id: 10117
rv_id: 1263944
rule_id: pKUGXr
version_id: e1TyjnR
url: https://semgrep.dev/playground/r/e1TyjnR/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service
origin: community
languages:
- yaml
severity: WARNING
- id: ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli
mode: taint
pattern-propagators:
- pattern: $X << $Y
from: $Y
to: $X
pattern-sources:
- pattern-either:
- pattern: |
params
- pattern: |
cookies
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
$CON = PG.connect(...)
...
- pattern-inside: |
$CON = PG::Connection.open(...)
...
- pattern-inside: |
$CON = PG::Connection.new(...)
...
- pattern-either:
- pattern: |
$CON.$METHOD($X,...)
- pattern: |
$CON.$METHOD $X, ...
- focus-metavariable: $X
- metavariable-regex:
metavariable: $METHOD
regex: ^(exec|exec_params)$
languages:
- ruby
message: 'Detected string concatenation with a non-literal variable in a pg Ruby
SQL statement. This could lead to SQL injection if the variable is user-controlled
and not properly sanitized. In order to prevent SQL injection, use parameterized
queries or prepared statements instead. You can use parameterized queries like
so: `conn.exec_params(''SELECT $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])` And
you can use prepared statements with `exec_prepared`.'
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://www.rubydoc.info/gems/pg/PG/Connection
category: security
technology:
- rails
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli
shortlink: https://sg.run/kL0o
semgrep.dev:
rule:
r_id: 10328
rv_id: 1263628
rule_id: NbUAz7
version_id: 2KTv2y2
url: https://semgrep.dev/playground/r/2KTv2y2/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli
origin: community
severity: WARNING
- id: java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled
pattern: management.endpoints.web.exposure.include=*
message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints
such as /actuator/env, /actuator/logfile, /actuator/heapdump and others. Unless
you have Spring Security enabled or another means to protect these endpoints,
this functionality is available without authentication, causing a significant
security risk.
severity: ERROR
languages:
- generic
paths:
include:
- '*properties'
metadata:
cwe:
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints
- https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785
- https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators
category: security
technology:
- spring
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled
shortlink: https://sg.run/L0vY
semgrep.dev:
rule:
r_id: 10439
rv_id: 1263077
rule_id: EwU4vg
version_id: xyTjzwp
url: https://semgrep.dev/playground/r/xyTjzwp/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled
origin: community
- id: generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling
patterns:
- pattern-either:
- pattern: |
proxy_http_version 1.1 ...;
...
proxy_set_header Upgrade ...;
...
proxy_set_header Connection ...;
- pattern: |
proxy_set_header Upgrade ...;
...
proxy_set_header Connection ...;
...
proxy_http_version 1.1 ...;
- pattern: |
proxy_set_header Upgrade ...;
...
proxy_http_version 1.1 ...;
...
proxy_set_header Connection ...;
- pattern-inside: |
location ... {
...
}
languages:
- generic
severity: WARNING
message: 'Conditions for Nginx H2C smuggling identified. H2C smuggling allows upgrading
HTTP/1.1 connections to lesser-known HTTP/2 over cleartext (h2c) connections which
can allow a bypass of reverse proxy access controls, and lead to long-lived, unrestricted
HTTP traffic directly to back-end servers. To mitigate: WebSocket support required:
Allow only the value websocket for HTTP/1.1 upgrade headers (e.g., Upgrade: websocket).
WebSocket support not required: Do not forward Upgrade headers.'
paths:
include:
- '*.conf'
- '*.vhost'
- '**/sites-available/*'
- '**/sites-enabled/*'
metadata:
cwe:
- 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response
Smuggling'')'
references:
- https://labs.bishopfox.com/tech-blog/h2c-smuggling-request-smuggling-via-http/2-cleartext-h2c
category: security
technology:
- nginx
confidence: MEDIUM
owasp:
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling
shortlink: https://sg.run/ploZ
semgrep.dev:
rule:
r_id: 10562
rv_id: 1262679
rule_id: 6JUq0Z
version_id: nWT2Lyp
url: https://semgrep.dev/playground/r/nWT2Lyp/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling
origin: community
- id: csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization
severity: WARNING
languages:
- C#
metadata:
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
references:
- https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide
category: security
technology:
- .net
confidence: HIGH
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization
shortlink: https://sg.run/ZeXW
semgrep.dev:
rule:
r_id: 11135
rv_id: 1262635
rule_id: bwUOjK
version_id: nWT2LGp
url: https://semgrep.dev/playground/r/nWT2LGp/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization
origin: community
message: The BinaryFormatter type is dangerous and is not recommended for data processing.
Applications should stop using BinaryFormatter as soon as possible, even if they
believe the data they're processing to be trustworthy. BinaryFormatter is insecure
and can't be made secure
patterns:
- pattern-inside: |
using System.Runtime.Serialization.Formatters.Binary;
...
- pattern: |
new BinaryFormatter();
- id: csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization
severity: WARNING
languages:
- C#
metadata:
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
references:
- https://mbraceproject.github.io/FsPickler/tutorial.html#Disabling-Subtype-Resolution
category: security
technology:
- .net
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization
shortlink: https://sg.run/E5e5
semgrep.dev:
rule:
r_id: 11137
rv_id: 1262638
rule_id: kxURnR
version_id: LjTkgPk
url: https://semgrep.dev/playground/r/LjTkgPk/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization
origin: community
message: The FsPickler is dangerous and is not recommended for data processing.
Default configuration tend to insecure deserialization vulnerability.
patterns:
- pattern-inside: |
using MBrace.FsPickler.Json;
...
- pattern: |
FsPickler.CreateJsonSerializer();
- id: csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization
severity: WARNING
languages:
- C#
metadata:
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
references:
- https://docs.microsoft.com/en-us/dotnet/api/system.web.ui.losformatter?view=netframework-4.8
category: security
technology:
- .net
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization
shortlink: https://sg.run/70pG
semgrep.dev:
rule:
r_id: 11138
rv_id: 1262641
rule_id: wdU87G
version_id: QkTGqnA
url: https://semgrep.dev/playground/r/QkTGqnA/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization
origin: community
message: The LosFormatter type is dangerous and is not recommended for data processing.
Applications should stop using LosFormatter as soon as possible, even if they
believe the data they're processing to be trustworthy. LosFormatter is insecure
and can't be made secure
patterns:
- pattern-inside: |
using System.Web.UI;
...
- pattern: |
new LosFormatter();
- id: csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization
severity: WARNING
languages:
- C#
metadata:
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
references:
- https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.netdatacontractserializer?view=netframework-4.8#security
category: security
technology:
- .net
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization
shortlink: https://sg.run/L0AX
semgrep.dev:
rule:
r_id: 11139
rv_id: 1262642
rule_id: x8UW7x
version_id: 3ZT4X6b
url: https://semgrep.dev/playground/r/3ZT4X6b/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization
origin: community
message: The NetDataContractSerializer type is dangerous and is not recommended
for data processing. Applications should stop using NetDataContractSerializer
as soon as possible, even if they believe the data they're processing to be trustworthy.
NetDataContractSerializer is insecure and can't be made secure
patterns:
- pattern-inside: |
using System.Runtime.Serialization;
...
- pattern: |
new NetDataContractSerializer();
- id: csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization
severity: WARNING
languages:
- C#
metadata:
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
references:
- https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.formatters.soap.soapformatter?view=netframework-4.8#remarks
category: security
technology:
- .net
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization
shortlink: https://sg.run/gJnR
semgrep.dev:
rule:
r_id: 11141
rv_id: 1262644
rule_id: eqUvND
version_id: PkTR30n
url: https://semgrep.dev/playground/r/PkTR30n/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization
origin: community
message: The SoapFormatter type is dangerous and is not recommended for data processing.
Applications should stop using SoapFormatter as soon as possible, even if they
believe the data they're processing to be trustworthy. SoapFormatter is insecure
and can't be made secure
patterns:
- pattern-inside: |
using System.Runtime.Serialization.Formatters.Soap;
...
- pattern: |
new SoapFormatter();
- id: terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional
languages:
- hcl
message: AWS EC2 Instance allowing use of the IMDSv1
metadata:
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
references:
- https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/instance#metadata-options
category: security
technology:
- terraform
- aws
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional
shortlink: https://sg.run/J3BQ
semgrep.dev:
rule:
r_id: 11302
rv_id: 1263884
rule_id: GdU0eA
version_id: w8TRooE
url: https://semgrep.dev/playground/r/w8TRooE/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional
origin: community
pattern-either:
- patterns:
- pattern: http_tokens = "optional"
- pattern-inside: |
metadata_options { ... }
- patterns:
- pattern: |
resource "aws_instance" "$NAME" {
...
}
- pattern-not: |
resource "aws_instance" "$NAME" {
...
metadata_options {
...
http_tokens = "required"
...
}
...
}
- pattern-not: |
resource "aws_instance" "$NAME" {
...
metadata_options {
...
http_tokens = "optional"
...
}
...
}
- pattern-not: |
resource "aws_instance" "$NAME" {
...
metadata_options {
...
http_endpoint = "disabled"
...
}
...
}
severity: ERROR
- id: java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse
metadata:
functional-categories:
- crypto::search::randomness::javax.crypto
cwe:
- 'CWE-323: Reusing a Nonce, Key Pair in Encryption'
category: security
source-rule-url: https://www.youtube.com/watch?v=r1awgAl90wM
technology:
- java
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse
shortlink: https://sg.run/Dww2
semgrep.dev:
rule:
r_id: 11908
rv_id: 1263000
rule_id: GdUZZ3
version_id: 0bTKzGk
url: https://semgrep.dev/playground/r/0bTKzGk/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse
origin: community
languages:
- java
message: 'GCM IV/nonce is reused: encryption can be totally useless'
patterns:
- pattern-either:
- pattern: new GCMParameterSpec(..., "...".getBytes(...), ...);
- pattern: byte[] $NONCE = "...".getBytes(...); ... new GCMParameterSpec(...,
$NONCE, ...);
severity: ERROR
- id: csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos
severity: WARNING
languages:
- C#
metadata:
cwe:
- 'CWE-1333: Inefficient Regular Expression Complexity'
owasp: A01:2017 - Injection
references:
- https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS
- https://docs.microsoft.com/en-us/dotnet/standard/base-types/regular-expressions#regular-expression-examples
category: security
technology:
- .net
confidence: MEDIUM
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Denial-of-Service (DoS)
source: https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos
shortlink: https://sg.run/RPyY
semgrep.dev:
rule:
r_id: 12005
rv_id: 945225
rule_id: 4bU2gd
version_id: rxT6rjl
url: https://semgrep.dev/playground/r/rxT6rjl/csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos
origin: community
message: When using `System.Text.RegularExpressions` to process untrusted input,
pass a timeout. A malicious user can provide input to `RegularExpressions` that
abuses the backtracking behaviour of this regular expression engine. This will
lead to excessive CPU usage, causing a Denial-of-Service attack
patterns:
- pattern-inside: |
using System.Text.RegularExpressions;
...
- pattern-either:
- pattern: |
public $T $F($X)
{
Regex $Y = new Regex($P);
...
$Y.Match($X);
}
- pattern: |
public $T $F($X)
{
Regex $Y = new Regex($P, $O);
...
$Y.Match($X);
}
- pattern: |
public $T $F($X)
{
... Regex.Match($X, $P);
}
- pattern: |
public $T $F($X)
{
... Regex.Match($X, $P, $O);
}
- id: javascript.express.security.express-vm-injection.express-vm-injection
message: Make sure that unverified user data can not reach `$VM`.
metadata:
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
category: security
technology:
- express
cwe2022-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/javascript.express.security.express-vm-injection.express-vm-injection
shortlink: https://sg.run/jkqJ
semgrep.dev:
rule:
r_id: 12821
rv_id: 1263170
rule_id: DbUKPX
version_id: 1QTypXQ
url: https://semgrep.dev/playground/r/1QTypXQ/javascript.express.security.express-vm-injection.express-vm-injection
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-inside: |
$VM = require('vm');
...
- pattern-either:
- pattern: |
$VM.runInContext(...)
- pattern: |
$VM.runInNewContext(...)
- pattern: |
$VM.compileFunction(...)
- pattern: |
$VM.runInThisContext(...)
- pattern: new $VM.Script(...)
- id: javascript.express.security.express-vm2-injection.express-vm2-injection
message: Make sure that unverified user data can not reach `vm2`.
metadata:
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
category: security
technology:
- express
cwe2022-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/javascript.express.security.express-vm2-injection.express-vm2-injection
shortlink: https://sg.run/1GWv
semgrep.dev:
rule:
r_id: 12822
rv_id: 1263171
rule_id: WAUPXJ
version_id: 9lT4bnX
url: https://semgrep.dev/playground/r/9lT4bnX/javascript.express.security.express-vm2-injection.express-vm2-injection
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-inside: |
require('vm2')
...
- pattern-either:
- patterns:
- pattern-either:
- pattern-inside: |
$VM = new VM(...)
...
- pattern-inside: |
$VM = new NodeVM(...)
...
- pattern: |
$VM.run(...)
- pattern: |
new VM(...).run(...)
- pattern: |
new NodeVM(...).run(...)
- pattern: |
new VMScript(...)
- pattern: |
new VM(...)
- pattern: new NodeVM(...)
- id: javascript.lang.security.audit.code-string-concat.code-string-concat
message: Found data from an Express or Next web request flowing to `eval`. If this
data is user-controllable this can lead to execution of arbitrary system commands
in the context of your application process. Avoid `eval` whenever possible.
options:
interfile: true
metadata:
interfile: true
confidence: HIGH
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
references:
- https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval
- https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback
- https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/
- https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html
category: security
technology:
- node.js
- Express
- Next.js
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat
shortlink: https://sg.run/96Yk
semgrep.dev:
rule:
r_id: 13023
rv_id: 1263192
rule_id: DbUKEz
version_id: 44TEjYX
url: https://semgrep.dev/playground/r/44TEjYX/javascript.lang.security.audit.code-string-concat.code-string-concat
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- pattern-either:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT)
{...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
import { ...,$IMPORT,... } from 'next/router'
...
- pattern-inside: |
import $IMPORT from 'next/router';
...
- pattern-either:
- patterns:
- pattern-inside: |
$ROUTER = $IMPORT()
...
- pattern-either:
- pattern-inside: |
const { ...,$PROPS,... } = $ROUTER.query
...
- pattern-inside: |
var { ...,$PROPS,... } = $ROUTER.query
...
- pattern-inside: |
let { ...,$PROPS,... } = $ROUTER.query
...
- focus-metavariable: $PROPS
- patterns:
- pattern-inside: |
$ROUTER = $IMPORT()
...
- pattern: "$ROUTER.query.$VALUE \n"
- patterns:
- pattern: $IMPORT().query.$VALUE
pattern-sinks:
- patterns:
- pattern: |
eval(...)
- id: yaml.github-actions.security.run-shell-injection.run-shell-injection
languages:
- yaml
message: 'Using variable interpolation `${{...}}` with `github` context data in
a `run:` step could allow an attacker to inject their own code into the runner.
This would allow them to steal secrets and code. `github` context data can have
arbitrary user input and should be treated as untrusted. Instead, use an intermediate
environment variable with `env:` to store the data and use the environment variable
in the `run:` script. Be sure to use double-quotes the environment variable, like
this: "$ENVVAR".'
metadata:
category: security
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections
- https://securitylab.github.com/research/github-actions-untrusted-input/
technology:
- github-actions
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/yaml.github-actions.security.run-shell-injection.run-shell-injection
shortlink: https://sg.run/pkzk
semgrep.dev:
rule:
r_id: 13162
rv_id: 1423395
rule_id: v8UjQj
version_id: GxTl1DQ
url: https://semgrep.dev/playground/r/GxTl1DQ/yaml.github-actions.security.run-shell-injection.run-shell-injection
origin: community
patterns:
- pattern-inside: 'steps: [...]'
- pattern-inside: |
- run: ...
...
- pattern: 'run: $SHELL'
- metavariable-pattern:
language: generic
metavariable: $SHELL
patterns:
- pattern-either:
- pattern: ${{ ... github.event.issue.title ... }}
- pattern: ${{ ... github.event.issue.body ... }}
- pattern: ${{ ... github.event.pull_request.title ... }}
- pattern: ${{ ... github.event.pull_request.body ... }}
- pattern: ${{ ... github.event.comment.body ... }}
- pattern: ${{ ... github.event.review.body ... }}
- pattern: ${{ ... github.event.review_comment.body ... }}
- pattern: ${{ ... github.event.pages ... .page_name ... }}
- pattern: ${{ ... github.event.head_commit.message ... }}
- pattern: ${{ ... github.event.head_commit.author.email ... }}
- pattern: ${{ ... github.event.head_commit.author.name ... }}
- pattern: ${{ ... github.event.commits ... .author.email ... }}
- pattern: ${{ ... github.event.commits ... .author.name ... }}
- pattern: ${{ ... github.event.commits ... .message ... }}
- pattern: ${{ ... github.event.pull_request.head.ref ... }}
- pattern: ${{ ... github.event.pull_request.head.label ... }}
- pattern: ${{ ... github.event.pull_request.head.repo.default_branch ...
}}
- pattern: ${{ ... github.ref ... }}
- pattern: ${{ ... github.base_ref ... }}
- pattern: ${{ ... github.head_ref ... }}
- pattern: ${{ ... github.ref_name ... }}
- pattern: ${{ ... github.workflow ... }}
- pattern: ${{ ... github.event.inputs ... }}
- pattern: ${{ ... github.event.discussion.title ... }}
- pattern: ${{ ... github.event.discussion.body ... }}
- pattern: ${{ ... github.event.workflow_run.head_branch ... }}
- pattern: ${{ ... github.event.workflow_run.head_commit.message ... }}
- pattern: ${{ ... github.event.milestone.title ... }}
- pattern: ${{ ... github.event.milestone.description ... }}
- pattern: ${{ ... github.event.project_card.note ... }}
- pattern: ${{ ... github.event.project.name ... }}
- pattern: ${{ ... github.event.project_column.name ... }}
- pattern: ${{ ... github.event.release.name ... }}
- pattern: ${{ ... github.event.release.body ... }}
- pattern: ${{ ... github.event.deployment.ref ... }}
- pattern: ${{ ... inputs ... }}
- pattern-not: ${{ ... github.event.issue.title && ... }}
- pattern-not: ${{ ... github.event.issue.body && ... }}
- pattern-not: ${{ ... github.event.pull_request.title && ... }}
- pattern-not: ${{ ... github.event.pull_request.body && ... }}
- pattern-not: ${{ ... github.event.comment.body && ... }}
- pattern-not: ${{ ... github.event.review.body && ... }}
- pattern-not: ${{ ... github.event.review_comment.body && ... }}
- pattern-not: ${{ ... github.event.pages ... .page_name && ... }}
- pattern-not: ${{ ... github.event.head_commit.message && ... }}
- pattern-not: ${{ ... github.event.head_commit.author.email && ... }}
- pattern-not: ${{ ... github.event.head_commit.author.name && ... }}
- pattern-not: ${{ ... github.event.commits ... .author.email && ... }}
- pattern-not: ${{ ... github.event.commits ... .author.name && ... }}
- pattern-not: ${{ ... github.event.commits ... .message && ... }}
- pattern-not: ${{ ... github.event.pull_request.head.ref && ... }}
- pattern-not: ${{ ... github.event.pull_request.head.label && ... }}
- pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch &&
... }}
- pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ...
}}
- pattern-not: ${{ ... github.ref && ... }}
- pattern-not: ${{ ... github.base_ref && ... }}
- pattern-not: ${{ ... github.head_ref && ... }}
- pattern-not: ${{ ... github.ref_name && ... }}
- pattern-not: ${{ ... github.workflow && ... }}
- pattern-not: ${{ ... github.event.inputs && ... }}
- pattern-not: ${{ ... github.event.discussion.title && ... }}
- pattern-not: ${{ ... github.event.discussion.body && ... }}
- pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }}
- pattern-not: ${{ ... github.event.milestone.title && ... }}
- pattern-not: ${{ ... github.event.milestone.description && ... }}
- pattern-not: ${{ ... github.event.project_card.note && ... }}
- pattern-not: ${{ ... github.event.project.name && ... }}
- pattern-not: ${{ ... github.event.project_column.name && ... }}
- pattern-not: ${{ ... github.event.release.name && ... }}
- pattern-not: ${{ ... github.event.release.body && ... }}
- pattern-not: ${{ ... github.event.deployment.ref && ... }}
severity: ERROR
- id: yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout
languages:
- yaml
message: This GitHub Actions workflow file uses `pull_request_target` and checks
out code from the incoming pull request. When using `pull_request_target`, the
Action runs in the context of the target repository, which includes access to
all repository secrets. Normally, this is safe because the Action only runs code
from the target repository, not the incoming PR. However, by checking out the
incoming PR code, you're now using the incoming code for the rest of the action.
You may be inadvertently executing arbitrary code from the incoming PR with access
to repository secrets, which would let an attacker steal repository secrets. This
normally happens by running build scripts (e.g., `npm build` and `make`) or dependency
installation scripts (e.g., `python setup.py install`). Audit your workflow file
to make sure no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
for additional mitigations.
metadata:
category: security
owasp:
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software and Data Integrity Failures
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
references:
- https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
- https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target
- https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md
technology:
- github-actions
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout
shortlink: https://sg.run/jkdn
semgrep.dev:
rule:
r_id: 13365
rv_id: 1413423
rule_id: d8Ulkd
version_id: O9TQ2nX
url: https://semgrep.dev/playground/r/O9TQ2nX/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout
origin: community
patterns:
- pattern-either:
- pattern-inside: |
on:
...
pull_request_target: ...
...
...
- pattern-inside: |
on: [..., pull_request_target, ...]
...
- pattern-inside: |
on: pull_request_target
...
- pattern-inside: |
jobs:
...
$JOBNAME:
...
steps:
...
- pattern: |
...
uses: "$ACTION"
with:
...
ref: $EXPR
- metavariable-regex:
metavariable: $ACTION
regex: actions/checkout@.*
- metavariable-pattern:
language: generic
metavariable: $EXPR
patterns:
- pattern-inside: ${{ ... }}
- pattern-either:
- pattern: github.event.pull_request ...
- pattern: github.head_ref ...
severity: ERROR
- id: yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands
languages:
- yaml
severity: WARNING
message: The environment variable `ACTIONS_ALLOW_UNSECURE_COMMANDS` grants this
workflow permissions to use the `set-env` and `add-path` commands. There is a
vulnerability in these commands that could result in environment variables being
modified by an attacker. Depending on the use of the environment variable, this
could enable an attacker to, at worst, modify the system path to run a different
command than intended, resulting in arbitrary code execution. This could result
in stolen code or secrets. Don't use `ACTIONS_ALLOW_UNSECURE_COMMANDS`. Instead,
use Environment Files. See https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files
for more information.
metadata:
cwe:
- 'CWE-749: Exposed Dangerous Method or Function'
owasp: A06:2017 - Security Misconfiguration
references:
- https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/
- https://github.com/actions/toolkit/security/advisories/GHSA-mfwh-5m23-j46w
- https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files
category: security
technology:
- github-actions
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Dangerous Method or Function
source: https://semgrep.dev/r/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands
shortlink: https://sg.run/qq78
semgrep.dev:
rule:
r_id: 13412
rv_id: 947039
rule_id: EwUQ9x
version_id: jQTzq34
url: https://semgrep.dev/playground/r/jQTzq34/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands
origin: community
patterns:
- pattern-either:
- patterns:
- pattern-inside: '{env: ...}'
- pattern: 'ACTIONS_ALLOW_UNSECURE_COMMANDS: true'
- id: json.aws.security.public-s3-bucket.public-s3-bucket
languages:
- json
message: Detected public S3 bucket. This policy allows anyone to have some kind
of access to the bucket. The exact level of access and types of actions allowed
will depend on the configuration of bucket policy and ACLs. Please review the
bucket configuration to make sure they are set with intended values.
metadata:
category: security
cwe:
- 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html
technology:
- aws
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/json.aws.security.public-s3-bucket.public-s3-bucket
shortlink: https://sg.run/lxv5
semgrep.dev:
rule:
r_id: 13413
rv_id: 1263254
rule_id: 7KUpLy
version_id: RGT0Ld0
url: https://semgrep.dev/playground/r/RGT0Ld0/json.aws.security.public-s3-bucket.public-s3-bucket
origin: community
patterns:
- pattern-inside: |
$BUCKETNAME: {
"Type": "AWS::S3::Bucket",
"Properties": {
...,
},
...,
}
- pattern-either:
- pattern: |
"PublicAccessBlockConfiguration": {
...,
"RestrictPublicBuckets": false,
...,
},
- pattern: |
"PublicAccessBlockConfiguration": {
...,
"IgnorePublicAcls": false,
...,
},
- pattern: |
"PublicAccessBlockConfiguration": {
...,
"BlockPublicAcls": false,
...,
},
- pattern: |
"PublicAccessBlockConfiguration": {
...,
"BlockPublicPolicy": false,
...,
},
severity: WARNING
- id: javascript.express.security.cors-misconfiguration.cors-misconfiguration
message: By letting user input control CORS parameters, there is a risk that software
does not properly verify that the source of data or communication is valid. Use
literal values for CORS settings.
metadata:
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe:
- 'CWE-346: Origin Validation Error'
category: security
references:
- https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS
technology:
- express
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/javascript.express.security.cors-misconfiguration.cors-misconfiguration
shortlink: https://sg.run/nKXO
semgrep.dev:
rule:
r_id: 13580
rv_id: 1263162
rule_id: 5rULJQ
version_id: YDTZe8Y
url: https://semgrep.dev/playground/r/YDTZe8Y/javascript.express.security.cors-misconfiguration.cors-misconfiguration
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-either:
- pattern: $RES.set($HEADER, $X)
- pattern: $RES.header($HEADER, $X)
- pattern: $RES.setHeader($HEADER, $X)
- pattern: |
$RES.set({$HEADER: $X}, ...)
- pattern: |
$RES.writeHead($STATUS, {$HEADER: $X}, ...)
- focus-metavariable: $X
- metavariable-regex:
metavariable: $HEADER
regex: .*(Access-Control-Allow-Origin|access-control-allow-origin).*
- id: javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration
message: By letting user input control `X-Frame-Options` header, there is a risk
that software does not properly verify whether or not a browser should be allowed
to render a page in an `iframe`.
metadata:
references:
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options
owasp:
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
cwe:
- 'CWE-451: User Interface (UI) Misrepresentation of Critical Information'
category: security
technology:
- express
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration
shortlink: https://sg.run/EvjA
semgrep.dev:
rule:
r_id: 13581
rv_id: 1263178
rule_id: GdUrLy
version_id: xyTjz3D
url: https://semgrep.dev/playground/r/xyTjz3D/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-either:
- pattern: $RES.set($HEADER, ...)
- pattern: $RES.header($HEADER, ...)
- pattern: $RES.setHeader($HEADER, ...)
- pattern: |
$RES.set({$HEADER: ...}, ...)
- pattern: |
$RES.writeHead($STATUS, {$HEADER: ...}, ...)
- metavariable-regex:
metavariable: $HEADER
regex: .*(X-Frame-Options|x-frame-options).*
- id: ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation
metadata:
shortDescription: Allowing an attacker to manipulate the session may lead to unintended
behavior.
tags:
- security
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-276: Incorrect Default Permissions'
references:
- https://brakemanscanner.org/docs/warning_types/session_manipulation/
category: security
technology:
- rails
help: |
## Remediation
Session manipulation can occur when an application allows user-input in session keys. Since sessions are typically considered a source of truth (e.g. to check the logged-in user or to match CSRF tokens), allowing an attacker to manipulate the session may lead to unintended behavior.
## References
[Session Manipulation](https://brakemanscanner.org/docs/warning_types/session_manipulation/)
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation
shortlink: https://sg.run/86q7
semgrep.dev:
rule:
r_id: 13584
rv_id: 1263621
rule_id: BYUdW6
version_id: qkTR76G
url: https://semgrep.dev/playground/r/qkTR76G/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation
origin: community
message: This gets data from session using user inputs. A malicious user may be
able to retrieve information from your session that you didn't intend them to.
Do not use user input as a session key.
languages:
- ruby
severity: WARNING
mode: taint
pattern-sources:
- pattern: params
- pattern: cookies
- pattern: request.env
pattern-sinks:
- pattern: session[...]
- id: ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access
metadata:
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
references:
- https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown
category: security
technology:
- rails
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access
shortlink: https://sg.run/gYln
semgrep.dev:
rule:
r_id: 13585
rv_id: 1263622
rule_id: DbU1dr
version_id: l4TJRkk
url: https://semgrep.dev/playground/r/l4TJRkk/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access
origin: community
message: Using user input when accessing files is potentially dangerous. A malicious
actor could use this to modify or access files they have no right to.
languages:
- ruby
severity: WARNING
mode: taint
pattern-sources:
- pattern: params
- pattern: cookies
- pattern: request.env
pattern-sinks:
- patterns:
- pattern-either:
- pattern: Dir.$X(...)
- pattern: File.$X(...)
- pattern: IO.$X(...)
- pattern: Kernel.$X(...)
- pattern: PStore.$X(...)
- pattern: Pathname.$X(...)
- metavariable-pattern:
metavariable: $X
patterns:
- pattern-either:
- pattern: chdir
- pattern: chroot
- pattern: delete
- pattern: entries
- pattern: foreach
- pattern: glob
- pattern: install
- pattern: lchmod
- pattern: lchown
- pattern: link
- pattern: load
- pattern: load_file
- pattern: makedirs
- pattern: move
- pattern: new
- pattern: open
- pattern: read
- pattern: readlines
- pattern: rename
- pattern: rmdir
- pattern: safe_unlink
- pattern: symlink
- pattern: syscopy
- pattern: sysopen
- pattern: truncate
- pattern: unlink
- id: ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call
metadata:
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
references:
- https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown
category: security
technology:
- rails
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call
shortlink: https://sg.run/Q9gP
semgrep.dev:
rule:
r_id: 13586
rv_id: 1263623
rule_id: WAUyzp
version_id: YDTZeWL
url: https://semgrep.dev/playground/r/YDTZeWL/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call
origin: community
message: Using user input when accessing files is potentially dangerous. A malicious
actor could use this to modify or access files they have no right to.
languages:
- ruby
severity: WARNING
mode: taint
pattern-sources:
- pattern: params
- pattern: cookies
- pattern: request.env
pattern-sinks:
- pattern-either:
- pattern: Net::FTP.$X(...)
- patterns:
- pattern-inside: |
$FTP = Net::FTP.$OPEN(...)
...
$FTP.$METHOD(...)
- pattern: $FTP.$METHOD(...)
- id: ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request
metadata:
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
references:
- https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown
category: security
technology:
- rails
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request
shortlink: https://sg.run/3rLb
semgrep.dev:
rule:
r_id: 13587
rv_id: 1263624
rule_id: 0oU2x3
version_id: 6xT29nN
url: https://semgrep.dev/playground/r/6xT29nN/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request
origin: community
message: Using user input when accessing files is potentially dangerous. A malicious
actor could use this to modify or access files they have no right to.
languages:
- ruby
severity: WARNING
mode: taint
pattern-sources:
- pattern: params
- pattern: cookies
- pattern: request.env
pattern-sinks:
- pattern-either:
- patterns:
- pattern: Net::HTTP::$METHOD.new(...)
- metavariable-pattern:
metavariable: $METHOD
patterns:
- pattern-either:
- pattern: Copy
- pattern: Delete
- pattern: Get
- pattern: Head
- pattern: Lock
- pattern: Mkcol
- pattern: Move
- pattern: Options
- pattern: Patch
- pattern: Post
- pattern: Propfind
- pattern: Proppatch
- pattern: Put
- pattern: Trace
- pattern: Unlock
- patterns:
- pattern: Net::HTTP.$X(...)
- metavariable-pattern:
metavariable: $X
patterns:
- pattern-either:
- pattern: get
- pattern: get2
- pattern: head
- pattern: head2
- pattern: options
- pattern: patch
- pattern: post
- pattern: post2
- pattern: post_form
- pattern: put
- pattern: request
- pattern: request_get
- pattern: request_head
- pattern: request_post
- pattern: send_request
- pattern: trace
- pattern: get_print
- pattern: get_response
- pattern: start
- id: ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call
metadata:
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
references:
- https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown
category: security
technology:
- rails
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call
shortlink: https://sg.run/4e8E
semgrep.dev:
rule:
r_id: 13588
rv_id: 1263625
rule_id: KxU72k
version_id: o5TbDq8
url: https://semgrep.dev/playground/r/o5TbDq8/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call
origin: community
message: Using user input when accessing files is potentially dangerous. A malicious
actor could use this to modify or access files they have no right to.
languages:
- ruby
severity: ERROR
mode: taint
pattern-sources:
- pattern-either:
- pattern: params[...]
- pattern: cookies
- pattern: request.env
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: Kernel.$X(...)
- patterns:
- pattern-either:
- pattern: Shell.$X(...)
- patterns:
- pattern-inside: |
$SHELL = Shell.$ANY(...)
...
$SHELL.$X(...)
- pattern: $SHELL.$X(...)
- metavariable-pattern:
metavariable: $X
patterns:
- pattern-either:
- pattern: cat
- pattern: chdir
- pattern: chroot
- pattern: delete
- pattern: entries
- pattern: exec
- pattern: foreach
- pattern: glob
- pattern: install
- pattern: lchmod
- pattern: lchown
- pattern: link
- pattern: load
- pattern: load_file
- pattern: makedirs
- pattern: move
- pattern: new
- pattern: open
- pattern: read
- pattern: readlines
- pattern: rename
- pattern: rmdir
- pattern: safe_unlink
- pattern: symlink
- pattern: syscopy
- pattern: sysopen
- pattern: system
- pattern: truncate
- pattern: unlink
- id: ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_link_to.rb
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
references:
- https://brakemanscanner.org/docs/warning_types/link_to/
- https://brakemanscanner.org/docs/warning_types/link_to_href/
category: security
technology:
- rails
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to
shortlink: https://sg.run/JxXQ
semgrep.dev:
rule:
r_id: 13590
rv_id: 1263632
rule_id: lBU8Qj
version_id: 9lT4brj
url: https://semgrep.dev/playground/r/9lT4brj/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to
origin: community
message: This code includes user input in `link_to`. In Rails 2.x, the body of `link_to`
is not escaped. This means that user input which reaches the body will be executed
when the HTML is rendered. Even in other versions, values starting with `javascript:`
or `data:` are not escaped. It is better to create and use a safer function which
checks the body argument.
languages:
- ruby
severity: WARNING
mode: taint
pattern-sources:
- pattern: params
- pattern: cookies
- pattern: request.env
- pattern-either:
- pattern: $MODEL.url(...)
- pattern: $MODEL.uri(...)
- pattern: $MODEL.link(...)
- pattern: $MODEL.page(...)
- pattern: $MODEL.site(...)
pattern-sinks:
- pattern: link_to(...)
pattern-sanitizers:
- patterns:
- pattern: |
"...#{...}..."
- pattern-not: |
"#{...}..."
- id: ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect
metadata:
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
references:
- https://brakemanscanner.org/docs/warning_types/redirect/
category: security
technology:
- rails
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Open Redirect
source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect
shortlink: https://sg.run/5DY3
semgrep.dev:
rule:
r_id: 13591
rv_id: 1263634
rule_id: YGUDqJ
version_id: rxTAKdY
url: https://semgrep.dev/playground/r/rxTAKdY/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect
origin: community
message: When a redirect uses user input, a malicious user can spoof a website under
a trusted URL or access restricted parts of a site. When using user-supplied values,
sanitize the value before using it for the redirect.
languages:
- ruby
severity: WARNING
mode: taint
pattern-sources:
- pattern: params
- pattern: cookies
- pattern: request.env
- patterns:
- pattern: $MODEL.$X(...)
- pattern-not: $MODEL.$X("...")
- metavariable-pattern:
metavariable: $X
pattern-either:
- pattern: all
- pattern: create
- pattern: create!
- pattern: find
- pattern: find_by_sql
- pattern: first
- pattern: last
- pattern: new
- pattern: from
- pattern: group
- pattern: having
- pattern: joins
- pattern: lock
- pattern: order
- pattern: reorder
- pattern: select
- pattern: where
- pattern: find_by
- pattern: find_by!
- pattern: take
pattern-sinks:
- pattern: redirect_to(...)
pattern-sanitizers:
- pattern: params.merge(:only_path => true)
- pattern: params.merge(:host => ...)
- id: ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path
metadata:
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
references:
- https://brakemanscanner.org/docs/warning_types/dynamic_render_paths/
category: security
technology:
- rails
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path
shortlink: https://sg.run/GO2n
semgrep.dev:
rule:
r_id: 13592
rv_id: 1263635
rule_id: 6JU1bL
version_id: bZT53p0
url: https://semgrep.dev/playground/r/bZT53p0/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path
origin: community
message: Avoid rendering user input. It may be possible for a malicious user to
input a path that lets them access a template they shouldn't. To prevent this,
check dynamic template paths against a predefined allowlist to make sure it's
an allowed template.
languages:
- ruby
severity: WARNING
mode: taint
pattern-sources:
- pattern: params
- pattern: cookies
- pattern: request.env
pattern-sinks:
- patterns:
- pattern-inside: render($X => $INPUT, ...)
- pattern: $INPUT
- metavariable-pattern:
metavariable: $X
pattern-either:
- pattern: action
- pattern: template
- pattern: partial
- pattern: file
- id: python.lang.security.audit.insecure-file-permissions.insecure-file-permissions
languages:
- python
severity: WARNING
metadata:
category: security
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-276: Incorrect Default Permissions'
technology:
- python
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions
shortlink: https://sg.run/AXY4
semgrep.dev:
rule:
r_id: 13594
rv_id: 1263482
rule_id: zdUYqR
version_id: O9Tpxqr
url: https://semgrep.dev/playground/r/O9Tpxqr/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions
origin: community
message: These permissions `$BITS` are widely permissive and grant access to more
people than may be necessary. A good default is `0o644` which gives read and write
access to yourself and read access to everyone else.
patterns:
- pattern-inside: os.$METHOD(...)
- metavariable-pattern:
metavariable: $METHOD
patterns:
- pattern-either:
- pattern: chmod
- pattern: lchmod
- pattern: fchmod
- pattern-either:
- patterns:
- pattern: os.$METHOD($FILE, $BITS, ...)
- metavariable-comparison:
metavariable: $BITS
comparison: $BITS >= 0o650 and $BITS < 0o100000
- patterns:
- pattern: os.$METHOD($FILE, $BITS)
- metavariable-comparison:
metavariable: $BITS
comparison: $BITS >= 0o100650
- patterns:
- pattern: os.$METHOD($FILE, $BITS, ...)
- metavariable-pattern:
metavariable: $BITS
patterns:
- pattern-either:
- pattern: <... stat.S_IWGRP ...>
- pattern: <... stat.S_IXGRP ...>
- pattern: <... stat.S_IWOTH ...>
- pattern: <... stat.S_IXOTH ...>
- pattern: <... stat.S_IRWXO ...>
- pattern: <... stat.S_IRWXG ...>
- patterns:
- pattern: os.$METHOD($FILE, $EXPR | $MOD, ...)
- metavariable-comparison:
metavariable: $MOD
comparison: $MOD == 0o111
- id: php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query
languages:
- php
message: '`$QUERY` Detected string concatenation with a non-literal variable in
a Doctrine QueryBuilder method. This could lead to SQL injection if the variable
is user-controlled and not properly sanitized. In order to prevent SQL injection,
use parameterized queries or prepared statements instead.'
metadata:
category: security
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://www.doctrine-project.org/projects/doctrine-dbal/en/current/reference/query-builder.html#security-safely-preventing-sql-injection
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
technology:
- doctrine
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query
shortlink: https://sg.run/jwDJ
semgrep.dev:
rule:
r_id: 13965
rv_id: 1263271
rule_id: kxUw23
version_id: 1QTypnG
url: https://semgrep.dev/playground/r/1QTypnG/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query
origin: community
mode: taint
pattern-sinks:
- patterns:
- focus-metavariable: $SINK
- pattern-either:
- pattern: $QUERY->add(...,$SINK,...)
- pattern: $QUERY->select(...,$SINK,...)
- pattern: $QUERY->addSelect(...,$SINK,...)
- pattern: $QUERY->delete(...,$SINK,...)
- pattern: $QUERY->update(...,$SINK,...)
- pattern: $QUERY->insert(...,$SINK,...)
- pattern: $QUERY->from(...,$SINK,...)
- pattern: $QUERY->join(...,$SINK,...)
- pattern: $QUERY->innerJoin(...,$SINK,...)
- pattern: $QUERY->leftJoin(...,$SINK,...)
- pattern: $QUERY->rightJoin(...,$SINK,...)
- pattern: $QUERY->where(...,$SINK,...)
- pattern: $QUERY->andWhere(...,$SINK,...)
- pattern: $QUERY->orWhere(...,$SINK,...)
- pattern: $QUERY->groupBy(...,$SINK,...)
- pattern: $QUERY->addGroupBy(...,$SINK,...)
- pattern: $QUERY->having(...,$SINK,...)
- pattern: $QUERY->andHaving(...,$SINK,...)
- pattern: $QUERY->orHaving(...,$SINK,...)
- pattern: $QUERY->orderBy(...,$SINK,...)
- pattern: $QUERY->addOrderBy(...,$SINK,...)
- pattern: $QUERY->set($SINK,...)
- pattern: $QUERY->setValue($SINK,...)
- pattern-either:
- pattern-inside: |
$Q = $X->createQueryBuilder();
...
- pattern-inside: |
$Q = new QueryBuilder(...);
...
pattern-sources:
- patterns:
- pattern-either:
- pattern: sprintf(...)
- pattern: |
"...".$SMTH
severity: WARNING
- id: python.django.security.injection.raw-html-format.raw-html-format
languages:
- python
severity: WARNING
message: Detected user input flowing into a manually constructed HTML string. You
may be accidentally bypassing secure methods of rendering HTML by manually constructing
HTML and this could create a cross-site scripting vulnerability, which could let
attackers steal sensitive user data. To be sure this is safe, check that the HTML
is rendered safely. Otherwise, use templates (`django.shortcuts.render`) which
will safely render HTML instead.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- django
references:
- https://docs.djangoproject.com/en/3.2/topics/http/shortcuts/#render
- https://docs.djangoproject.com/en/3.2/topics/security/#cross-site-scripting-xss-protection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/python.django.security.injection.raw-html-format.raw-html-format
shortlink: https://sg.run/oYj1
semgrep.dev:
rule:
r_id: 14360
rv_id: 1263397
rule_id: 2ZUPER
version_id: 5PTo100
url: https://semgrep.dev/playground/r/5PTo100/python.django.security.injection.raw-html-format.raw-html-format
origin: community
mode: taint
pattern-sanitizers:
- pattern: django.utils.html.escape(...)
pattern-sources:
- patterns:
- pattern: request.$ANYTHING
- pattern-not: request.build_absolute_uri
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: '"$HTMLSTR" % ...'
- pattern: '"$HTMLSTR".format(...)'
- pattern: '"$HTMLSTR" + ...'
- pattern: f"$HTMLSTR{...}..."
- patterns:
- pattern-inside: |
$HTML = "$HTMLSTR"
...
- pattern-either:
- pattern: $HTML % ...
- pattern: $HTML.format(...)
- pattern: $HTML + ...
- metavariable-pattern:
metavariable: $HTMLSTR
language: generic
pattern: <$TAG ...
- id: python.flask.security.injection.raw-html-concat.raw-html-format
languages:
- python
severity: WARNING
message: Detected user input flowing into a manually constructed HTML string. You
may be accidentally bypassing secure methods of rendering HTML by manually constructing
HTML and this could create a cross-site scripting vulnerability, which could let
attackers steal sensitive user data. To be sure this is safe, check that the HTML
is rendered safely. Otherwise, use templates (`flask.render_template`) which will
safely render HTML instead.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- flask
references:
- https://flask.palletsprojects.com/en/2.0.x/security/#cross-site-scripting-xss
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/python.flask.security.injection.raw-html-concat.raw-html-format
shortlink: https://sg.run/Pb7e
semgrep.dev:
rule:
r_id: 14389
rv_id: 1409401
rule_id: GdUrJv
version_id: RGTEN1l
url: https://semgrep.dev/playground/r/RGTEN1l/python.flask.security.injection.raw-html-concat.raw-html-format
origin: community
mode: taint
pattern-sanitizers:
- pattern: jinja2.escape(...)
- pattern: flask.escape(...)
- patterns:
- pattern: flask.render_template($TPL, ...)
- metavariable-regex:
metavariable: $TPL
regex: .*\.html
pattern-sources:
- patterns:
- pattern-either:
- pattern: flask.request.$ANYTHING
- patterns:
- pattern-inside: |
@$APP.route(...)
def $FUNC(..., $ROUTEVAR, ...):
...
- pattern: $ROUTEVAR
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: '"$HTMLSTR" % ...'
- pattern: '"$HTMLSTR".format(...)'
- pattern: '"$HTMLSTR" + ...'
- pattern: f"$HTMLSTR{...}..."
- patterns:
- pattern-inside: |
$HTML = "$HTMLSTR"
...
- pattern-either:
- pattern: $HTML % ...
- pattern: $HTML.format(...)
- pattern: $HTML + ...
- metavariable-pattern:
metavariable: $HTMLSTR
language: generic
pattern: <$TAG ...
- id: go.lang.security.injection.tainted-url-host.tainted-url-host
languages:
- go
message: A request was found to be crafted from user-input `$REQUEST`. This can
lead to Server-Side Request Forgery (SSRF) vulnerabilities, potentially exposing
sensitive data. It is recommend where possible to not allow user-input to craft
the base request, but to be treated as part of the path or query parameter. When
user-input is necessary to craft the request, it is recommended to follow OWASP
best practices to prevent abuse, including using an allowlist.
options:
interfile: true
metadata:
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
references:
- https://goteleport.com/blog/ssrf-attacks/
category: security
technology:
- go
confidence: HIGH
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host
shortlink: https://sg.run/5DjW
semgrep.dev:
rule:
r_id: 14391
rv_id: 1262970
rule_id: AbUQLr
version_id: yeTxpOj
url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host
origin: community
mode: taint
pattern-sources:
- label: INPUT
patterns:
- pattern-either:
- pattern: |
($REQUEST : *http.Request).$ANYTHING
- pattern: |
($REQUEST : http.Request).$ANYTHING
- metavariable-regex:
metavariable: $ANYTHING
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
- label: CLEAN
requires: INPUT
patterns:
- pattern-either:
- pattern: |
"$URLSTR" + $INPUT
- patterns:
- pattern-either:
- pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...)
- pattern: fmt.Sprintf("$URLSTR", $INPUT, ...)
- pattern: fmt.Printf("$URLSTR", $INPUT, ...)
- metavariable-regex:
metavariable: $URLSTR
regex: .*//[a-zA-Z0-10]+\..*
pattern-sinks:
- requires: INPUT and not CLEAN
patterns:
- pattern-either:
- patterns:
- pattern-either:
- patterns:
- pattern-inside: |
$CLIENT := &http.Client{...}
...
- pattern: $CLIENT.$METHOD($URL, ...)
- pattern: http.$METHOD($URL, ...)
- metavariable-regex:
metavariable: $METHOD
regex: ^(Get|Head|Post|PostForm)$
- patterns:
- pattern: |
http.NewRequest("$METHOD", $URL, ...)
- metavariable-regex:
metavariable: $METHOD
regex: ^(GET|HEAD|POST|POSTFORM)$
- focus-metavariable: $URL
severity: WARNING
- id: go.lang.security.injection.raw-html-format.raw-html-format
languages:
- go
severity: WARNING
message: Detected user input flowing into a manually constructed HTML string. You
may be accidentally bypassing secure methods of rendering HTML by manually constructing
HTML and this could create a cross-site scripting vulnerability, which could let
attackers steal sensitive user data. Use the `html/template` package which will
safely render HTML instead, or inspect that the HTML is rendered safely.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- go
references:
- https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/go.lang.security.injection.raw-html-format.raw-html-format
shortlink: https://sg.run/3r1G
semgrep.dev:
rule:
r_id: 14443
rv_id: 1262968
rule_id: PeUonQ
version_id: 1QTyp2p
url: https://semgrep.dev/playground/r/1QTyp2p/go.lang.security.injection.raw-html-format.raw-html-format
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
($REQUEST : *http.Request).$ANYTHING
- pattern: |
($REQUEST : http.Request).$ANYTHING
- metavariable-regex:
metavariable: $ANYTHING
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
pattern-sanitizers:
- pattern: html.EscapeString(...)
pattern-sinks:
- patterns:
- pattern-either:
- pattern: fmt.Printf("$HTMLSTR", ...)
- pattern: fmt.Sprintf("$HTMLSTR", ...)
- pattern: fmt.Fprintf($W, "$HTMLSTR", ...)
- pattern: '"$HTMLSTR" + ...'
- metavariable-pattern:
metavariable: $HTMLSTR
language: generic
pattern: <$TAG ...
- id: ruby.rails.security.injection.raw-html-format.raw-html-format
languages:
- ruby
severity: WARNING
message: Detected user input flowing into a manually constructed HTML string. You
may be accidentally bypassing secure methods of rendering HTML by manually constructing
HTML and this could create a cross-site scripting vulnerability, which could let
attackers steal sensitive user data. Use the `render template` and make template
files which will safely render HTML instead, or inspect that the HTML is absolutely
rendered safely with a function like `sanitize`.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- rails
references:
- https://www.netsparker.com/blog/web-security/preventing-xss-ruby-on-rails-web-applications/
- https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/ruby.rails.security.injection.raw-html-format.raw-html-format
shortlink: https://sg.run/b2JQ
semgrep.dev:
rule:
r_id: 14470
rv_id: 1409408
rule_id: kxUwZX
version_id: qkTvgYY
url: https://semgrep.dev/playground/r/qkTvgYY/ruby.rails.security.injection.raw-html-format.raw-html-format
origin: community
mode: taint
pattern-sanitizers:
- pattern-either:
- pattern: sanitize(...)
- pattern: strip_tags(...)
pattern-sources:
- patterns:
- pattern-either:
- pattern: params
- pattern: request
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: |
$HTMLSTR
- pattern-regex: <\w+.*
- patterns:
- pattern-either:
- pattern: Kernel::sprintf("$HTMLSTR", ...)
- pattern: |
"$HTMLSTR" + $EXPR
- pattern: |
"$HTMLSTR" % $EXPR
- metavariable-pattern:
metavariable: $HTMLSTR
language: generic
pattern: <$TAG ...
- id: bash.curl.security.curl-eval.curl-eval
severity: WARNING
languages:
- bash
message: Data is being eval'd from a `curl` command. An attacker with control of
the server in the `curl` command could inject malicious code into the `eval`,
resulting in a system comrpomise. Avoid eval'ing untrusted data if you can. If
you must do this, consider checking the SHA sum of the content returned by the
server to verify its integrity.
metadata:
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
category: security
technology:
- bash
- curl
confidence: MEDIUM
references:
- https://owasp.org/Top10/A03_2021-Injection
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/bash.curl.security.curl-eval.curl-eval
shortlink: https://sg.run/0yqJ
semgrep.dev:
rule:
r_id: 14554
rv_id: 1262601
rule_id: KxU7Rq
version_id: JdTzxL2
url: https://semgrep.dev/playground/r/JdTzxL2/bash.curl.security.curl-eval.curl-eval
origin: community
mode: taint
pattern-sources:
- pattern: |
$(curl ...)
- pattern: |
`curl ...`
pattern-sinks:
- pattern: eval ...
- id: python.flask.security.injection.tainted-url-host.tainted-url-host
languages:
- python
message: User data flows into the host portion of this manually-constructed URL.
This could allow an attacker to send data to their own server, potentially exposing
sensitive data such as cookies or authorization information sent with this request.
They could also probe internal servers or other resources that the server running
this code can access. (This is called server-side request forgery, or SSRF.) Do
not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or
hardcode the correct host.
metadata:
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
category: security
technology:
- flask
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/python.flask.security.injection.tainted-url-host.tainted-url-host
shortlink: https://sg.run/RXpK
semgrep.dev:
rule:
r_id: 14649
rv_id: 1409403
rule_id: ReU3Wb
version_id: BjTy42w
url: https://semgrep.dev/playground/r/BjTy42w/python.flask.security.injection.tainted-url-host.tainted-url-host
origin: community
mode: taint
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: '"$URLSTR" % ...'
- metavariable-pattern:
metavariable: $URLSTR
language: generic
patterns:
- pattern-either:
- pattern: $SCHEME://%s
- pattern: $SCHEME://%r
- patterns:
- pattern: '"$URLSTR".format(...)'
- metavariable-pattern:
metavariable: $URLSTR
language: generic
pattern: $SCHEME:// { ... }
- patterns:
- pattern: '"$URLSTR" + ...'
- metavariable-regex:
metavariable: $URLSTR
regex: .*://$
- patterns:
- pattern: f"$URLSTR{...}..."
- metavariable-regex:
metavariable: $URLSTR
regex: .*://$
- patterns:
- pattern-inside: |
$URL = "$URLSTR"
...
- pattern: $URL += ...
- metavariable-regex:
metavariable: $URLSTR
regex: .*://$
pattern-sources:
- patterns:
- pattern-either:
- pattern: flask.request.$ANYTHING
- patterns:
- pattern-inside: |
@$APP.route(...)
def $FUNC(..., $ROUTEVAR, ...):
...
- pattern: $ROUTEVAR
severity: WARNING
- id: go.lang.security.audit.md5-used-as-password.md5-used-as-password
languages:
- go
severity: WARNING
message: It looks like MD5 is used as a password hash. MD5 is not considered a secure
password hash because it can be cracked by an attacker in a short amount of time.
Use a suitable password hashing function such as bcrypt. You can use the `golang.org/x/crypto/bcrypt`
package.
options:
interfile: true
metadata:
category: security
technology:
- md5
references:
- https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html
- https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords
- https://github.com/returntocorp/semgrep-rules/issues/1609
- https://pkg.go.dev/golang.org/x/crypto/bcrypt
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
confidence: MEDIUM
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/go.lang.security.audit.md5-used-as-password.md5-used-as-password
shortlink: https://sg.run/4eOE
semgrep.dev:
rule:
r_id: 14688
rv_id: 1262938
rule_id: 4bU1Wj
version_id: nWT2L9r
url: https://semgrep.dev/playground/r/nWT2L9r/go.lang.security.audit.md5-used-as-password.md5-used-as-password
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: md5.New
- pattern: md5.Sum
pattern-sinks:
- patterns:
- pattern: $FUNCTION(...)
- metavariable-regex:
metavariable: $FUNCTION
regex: (?i)(.*password.*)
- id: go.lang.security.injection.tainted-sql-string.tainted-sql-string
languages:
- go
message: User data flows into this manually-constructed SQL string. User data can
be safely inserted into SQL strings using prepared statements or an object-relational
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
injection, which could let an attacker steal or manipulate data from the database.
Instead, use prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`)
or a safe library.
options:
interfile: true
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://golang.org/doc/database/sql-injection
- https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/
category: security
technology:
- go
confidence: HIGH
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string
shortlink: https://sg.run/PbEq
semgrep.dev:
rule:
r_id: 14689
rv_id: 1409388
rule_id: PeUoqy
version_id: nWTQ5qD
url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string
origin: community
mode: taint
severity: ERROR
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
($REQUEST : *http.Request).$ANYTHING
- pattern: |
($REQUEST : http.Request).$ANYTHING
- metavariable-regex:
metavariable: $ANYTHING
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: |
"$SQLSTR" + ...
- patterns:
- pattern-inside: |
$VAR = "$SQLSTR";
...
- pattern: $VAR += ...
- patterns:
- pattern-inside: |
var $SB strings.Builder
...
- pattern-inside: |
$SB.WriteString("$SQLSTR")
...
$SB.String(...)
- pattern: |
$SB.WriteString(...)
- metavariable-regex:
metavariable: $SQLSTR
regex: (?i)(select|delete|insert|create|update|alter|drop).*
- patterns:
- pattern-either:
- pattern: fmt.Fprintf($F, "$SQLSTR", ...)
- pattern: fmt.Sprintf("$SQLSTR", ...)
- pattern: fmt.Printf("$SQLSTR", ...)
- metavariable-regex:
metavariable: $SQLSTR
regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).*
pattern-sanitizers:
- pattern-either:
- pattern: strconv.Atoi(...)
- pattern: |
($X: bool)
- id: java.lang.security.audit.md5-used-as-password.md5-used-as-password
languages:
- java
severity: WARNING
message: It looks like MD5 is used as a password hash. MD5 is not considered a secure
password hash because it can be cracked by an attacker in a short amount of time.
Use a suitable password hashing function such as PBKDF2 or bcrypt. You can use
`javax.crypto.SecretKeyFactory` with `SecretKeyFactory.getInstance("PBKDF2WithHmacSHA1")`
or, if using Spring, `org.springframework.security.crypto.bcrypt`.
metadata:
category: security
technology:
- java
- md5
references:
- https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html
- https://github.com/returntocorp/semgrep-rules/issues/1609
- https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#SecretKeyFactory
- https://docs.spring.io/spring-security/site/docs/current/api/org/springframework/security/crypto/bcrypt/BCryptPasswordEncoder.html
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.md5-used-as-password.md5-used-as-password
shortlink: https://sg.run/JxEQ
semgrep.dev:
rule:
r_id: 14690
rv_id: 1263029
rule_id: JDULAW
version_id: bZT53QB
url: https://semgrep.dev/playground/r/bZT53QB/java.lang.security.audit.md5-used-as-password.md5-used-as-password
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-inside: |
$TYPE $MD = MessageDigest.getInstance("MD5");
...
- pattern: $MD.digest(...);
pattern-sinks:
- patterns:
- pattern: $MODEL.$METHOD(...);
- metavariable-regex:
metavariable: $METHOD
regex: (?i)(.*password.*)
- id: javascript.express.security.injection.raw-html-format.raw-html-format
message: User data flows into the host portion of this manually-constructed HTML.
This can introduce a Cross-Site-Scripting (XSS) vulnerability if this comes from
user-provided input. Consider using a sanitization library such as DOMPurify to
sanitize the HTML within.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
category: security
technology:
- express
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/javascript.express.security.injection.raw-html-format.raw-html-format
shortlink: https://sg.run/5DO3
semgrep.dev:
rule:
r_id: 14691
rv_id: 1263175
rule_id: 5rUL0X
version_id: NdTzyQv
url: https://semgrep.dev/playground/r/NdTzyQv/javascript.express.security.injection.raw-html-format.raw-html-format
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- label: EXPRESS
patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- label: EXPRESSTS
patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
- label: CLEAN
by-side-effect: true
patterns:
- pattern-either:
- pattern: $A($SOURCE)
- pattern: $SANITIZE. ... .$A($SOURCE)
- pattern: $A. ... .$SANITIZE($SOURCE)
- focus-metavariable: $SOURCE
- metavariable-regex:
metavariable: $A
regex: (?i)(.*valid|.*sanitiz)
pattern-sinks:
- requires: (EXPRESS and not CLEAN) or (EXPRESSTS and not CLEAN)
patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: '"$HTMLSTR" + $EXPR'
- pattern: '"$HTMLSTR".concat(...)'
- pattern: util.format($HTMLSTR, ...)
- metavariable-pattern:
metavariable: $HTMLSTR
language: generic
pattern: <$TAG ...
- patterns:
- pattern: |
`...`
- pattern-regex: |
.*<\w+.*
- id: kotlin.lang.security.ecb-cipher.ecb-cipher
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE
category: security
technology:
- kotlin
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/kotlin.lang.security.ecb-cipher.ecb-cipher
shortlink: https://sg.run/DzLj
semgrep.dev:
rule:
r_id: 14696
rv_id: 1263263
rule_id: DbU1Zd
version_id: YDTZexg
url: https://semgrep.dev/playground/r/YDTZexg/kotlin.lang.security.ecb-cipher.ecb-cipher
origin: community
message: Cipher in ECB mode is detected. ECB mode produces the same output for the
same input each time which allows an attacker to intercept and replay the data.
Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY.
severity: WARNING
languages:
- kt
patterns:
- pattern-either:
- pattern: |
val $VAR : Cipher = $CIPHER.getInstance($MODE)
- pattern: |
var $VAR : Cipher = $CIPHER.getInstance($MODE)
- pattern: |
val $VAR = $CIPHER.getInstance($MODE)
- pattern: |
var $VAR = $CIPHER.getInstance($MODE)
- metavariable-regex:
metavariable: $MODE
regex: .*ECB.*
- id: kotlin.lang.security.no-null-cipher.no-null-cipher
pattern: NullCipher(...)
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
category: security
technology:
- kotlin
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/kotlin.lang.security.no-null-cipher.no-null-cipher
shortlink: https://sg.run/0ywb
semgrep.dev:
rule:
r_id: 14698
rv_id: 1263265
rule_id: 0oU2Yy
version_id: o5TbDPj
url: https://semgrep.dev/playground/r/o5TbDPj/kotlin.lang.security.no-null-cipher.no-null-cipher
origin: community
message: 'NullCipher was detected. This will not encrypt anything; the cipher text
will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING").
See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for
more information.'
severity: WARNING
languages:
- kt
- scala
- id: kotlin.lang.security.use-of-md5.use-of-md5
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
resistant and is therefore not suitable as a cryptographic signature. Use SHA256
or SHA3 instead.
languages:
- kt
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-328: Use of Weak Hash'
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5
category: security
technology:
- kotlin
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/kotlin.lang.security.use-of-md5.use-of-md5
shortlink: https://sg.run/4eQx
semgrep.dev:
rule:
r_id: 14700
rv_id: 1263267
rule_id: qNUXPj
version_id: pZT03Jd
url: https://semgrep.dev/playground/r/pZT03Jd/kotlin.lang.security.use-of-md5.use-of-md5
origin: community
pattern-either:
- pattern: |
java.security.MessageDigest.getInstance("MD5")
- pattern: |
org.apache.commons.codec.digest.DigestUtils.getMd5Digest()
- id: python.flask.security.injection.tainted-sql-string.tainted-sql-string
message: Detected user input used to manually construct a SQL string. This is usually
bad practice because manual construction could accidentally result in a SQL injection.
An attacker could use a SQL injection to steal or modify contents of the database.
Instead, use a parameterized query which is available by default in most database
engines. Alternatively, consider using an object-relational mapper (ORM) such
as SQLAlchemy which will protect your queries.
metadata:
cwe:
- 'CWE-704: Incorrect Type Conversion or Cast'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql
- https://www.tutorialspoint.com/sqlalchemy/sqlalchemy_quick_guide.htm
- https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-more-specific-text-with-table-expression-literal-column-and-expression-column
category: security
technology:
- sqlalchemy
- flask
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/python.flask.security.injection.tainted-sql-string.tainted-sql-string
shortlink: https://sg.run/JxZj
semgrep.dev:
rule:
r_id: 14702
rv_id: 1409402
rule_id: YGUDKQ
version_id: A8TEvb4
url: https://semgrep.dev/playground/r/A8TEvb4/python.flask.security.injection.tainted-sql-string.tainted-sql-string
origin: community
severity: ERROR
languages:
- python
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: flask.request.$ANYTHING
- patterns:
- pattern-inside: |
@$APP.route(...)
def $FUNC(..., $ROUTEVAR, ...):
...
- pattern: $ROUTEVAR
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
"$SQLSTR" + ...
- pattern: |
"$SQLSTR" % ...
- pattern: |
"$SQLSTR".format(...)
- pattern: |
f"$SQLSTR{...}..."
- metavariable-regex:
metavariable: $SQLSTR
regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*
- id: python.lang.security.audit.md5-used-as-password.md5-used-as-password
severity: WARNING
message: It looks like MD5 is used as a password hash. MD5 is not considered a secure
password hash because it can be cracked by an attacker in a short amount of time.
Use a suitable password hashing function such as scrypt. You can use `hashlib.scrypt`.
languages:
- python
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://tools.ietf.org/html/rfc6151
- https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
- https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords
- https://github.com/returntocorp/semgrep-rules/issues/1609
- https://docs.python.org/3/library/hashlib.html#hashlib.scrypt
category: security
technology:
- pycryptodome
- hashlib
- md5
subcategory:
- vuln
likelihood: HIGH
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.lang.security.audit.md5-used-as-password.md5-used-as-password
shortlink: https://sg.run/5DwD
semgrep.dev:
rule:
r_id: 14703
rv_id: 1263504
rule_id: 6JU1w1
version_id: WrTqKDz
url: https://semgrep.dev/playground/r/WrTqKDz/python.lang.security.audit.md5-used-as-password.md5-used-as-password
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: hashlib.md5
- pattern: hashlib.new(..., name="MD5", ...)
- pattern: Cryptodome.Hash.MD5
- pattern: Crypto.Hash.MD5
- pattern: cryptography.hazmat.primitives.hashes.MD5
pattern-sinks:
- patterns:
- pattern: $FUNCTION(...)
- metavariable-regex:
metavariable: $FUNCTION
regex: (?i)(.*password.*)
- id: ruby.lang.security.md5-used-as-password.md5-used-as-password
languages:
- ruby
severity: WARNING
message: It looks like MD5 is used as a password hash. MD5 is not considered a secure
password hash because it can be cracked by an attacker in a short amount of time.
Instead, use a suitable password hashing function such as bcrypt. You can use
the `bcrypt` gem.
metadata:
category: security
technology:
- md5
references:
- https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html
- https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords
- https://github.com/returntocorp/semgrep-rules/issues/1609
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/ruby.lang.security.md5-used-as-password.md5-used-as-password
shortlink: https://sg.run/GOZy
semgrep.dev:
rule:
r_id: 14704
rv_id: 1263611
rule_id: oqU4p2
version_id: JdTzx0e
url: https://semgrep.dev/playground/r/JdTzx0e/ruby.lang.security.md5-used-as-password.md5-used-as-password
origin: community
mode: taint
pattern-sources:
- pattern: Digest::MD5
pattern-sinks:
- patterns:
- pattern: $FUNCTION(...);
- metavariable-regex:
metavariable: $FUNCTION
regex: (?i)(.*password.*)
- id: json.aws.security.wildcard-assume-role.wildcard-assume-role
patterns:
- pattern-inside: |
"Statement": [...]
- pattern-inside: |
{..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...}
- pattern: |
"Principal": {..., "AWS": "*", ...}
message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone
with your AWS account ID and the name of the role can assume the role. Instead,
limit to a specific identity in your account, like this: `arn:aws:iam::<account_id>:root`.'
metadata:
cwe:
- 'CWE-250: Execution with Unnecessary Privileges'
category: security
technology:
- aws
references:
- https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/
owasp:
- A06:2017 - Security Misconfiguration
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/json.aws.security.wildcard-assume-role.wildcard-assume-role
shortlink: https://sg.run/7YEZ
semgrep.dev:
rule:
r_id: 15138
rv_id: 1263256
rule_id: JDULx5
version_id: BjTkZoy
url: https://semgrep.dev/playground/r/BjTkZoy/json.aws.security.wildcard-assume-role.wildcard-assume-role
origin: community
languages:
- json
severity: ERROR
- id: ruby.rails.security.injection.tainted-url-host.tainted-url-host
languages:
- ruby
severity: WARNING
message: User data flows into the host portion of this manually-constructed URL.
This could allow an attacker to send data to their own server, potentially exposing
sensitive data such as cookies or authorization information sent with this request.
They could also probe internal servers or other resources that the server running
this code can access. (This is called server-side request forgery, or SSRF.) Do
not allow arbitrary hosts. Use the `ssrf_filter` gem and guard the url construction
with `SsrfFilter(...)`, or create an allowlist for approved hosts.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- rails
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
- https://github.com/arkadiyt/ssrf_filter
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-url-host.tainted-url-host
shortlink: https://sg.run/RX3g
semgrep.dev:
rule:
r_id: 14705
rv_id: 1263668
rule_id: zdUY0W
version_id: 6xT29BN
url: https://semgrep.dev/playground/r/6xT29BN/ruby.rails.security.injection.tainted-url-host.tainted-url-host
origin: community
mode: taint
pattern-sanitizers:
- pattern: SsrfFilter
pattern-sources:
- patterns:
- pattern-either:
- pattern: params
- pattern: request
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: |
$URLSTR
- pattern-regex: \w+:\/\/#{.*}
- patterns:
- pattern-either:
- pattern: Kernel::sprintf("$URLSTR", ...)
- pattern: |
"$URLSTR" + $EXPR
- pattern: |
"$URLSTR" % $EXPR
- metavariable-pattern:
metavariable: $URLSTR
language: generic
pattern: $SCHEME:// ...
- id: terraform.aws.security.wildcard-assume-role.wildcard-assume-role
patterns:
- pattern-inside: |
resource "aws_iam_role" $NAME {
...
}
- pattern: assume_role_policy = "$STATEMENT"
- metavariable-pattern:
metavariable: $STATEMENT
language: json
patterns:
- pattern-inside: |
{..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...}
- pattern: |
"Principal": {..., "AWS": "*", ...}
message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone
with your AWS account ID and the name of the role can assume the role. Instead,
limit to a specific identity in your account, like this: `arn:aws:iam::<account_id>:root`.'
metadata:
cwe:
- 'CWE-250: Execution with Unnecessary Privileges'
category: security
technology:
- aws
references:
- https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/
owasp:
- A06:2017 - Security Misconfiguration
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/terraform.aws.security.wildcard-assume-role.wildcard-assume-role
shortlink: https://sg.run/LXWr
semgrep.dev:
rule:
r_id: 15139
rv_id: 1263749
rule_id: 5rUL1P
version_id: LjTkg8D
url: https://semgrep.dev/playground/r/LjTkg8D/terraform.aws.security.wildcard-assume-role.wildcard-assume-role
origin: community
languages:
- hcl
severity: ERROR
- id: terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy
message: 'Azure Storage currently supports three versions of the TLS protocol: 1.0,
1.1, and 1.2. Azure Storage uses TLS 1.2 on public HTTPS endpoints, but TLS 1.0
and TLS 1.1 are still supported for backward compatibility. This check will warn
if the minimum TLS is not set to TLS1_2.'
patterns:
- pattern-either:
- pattern-inside: |
resource "azurerm_storage_account" "..." {
...
min_tls_version = "$ANYTHING"
...
}
- pattern-inside: |
resource "azurerm_storage_account" "..." {
...
}
- pattern-not-inside: |
resource "azurerm_storage_account" "..." {
...
min_tls_version = "TLS1_2"
...
}
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
category: security
technology:
- terraform
- azure
references:
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#min_tls_version
- https://docs.microsoft.com/en-us/azure/storage/common/transport-layer-security-configure-minimum-version
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy
shortlink: https://sg.run/KXD7
semgrep.dev:
rule:
r_id: 15155
rv_id: 1263807
rule_id: AbUQdL
version_id: WrTqKpv
url: https://semgrep.dev/playground/r/WrTqKpv/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy
origin: community
languages:
- hcl
severity: ERROR
- id: scala.lang.security.audit.rsa-padding-set.rsa-padding-set
metadata:
cwe:
- 'CWE-780: Use of RSA Algorithm without OAEP'
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
category: security
technology:
- scala
- cryptography
resources:
- https://blog.codacy.com/9-scala-security-issues/
confidence: HIGH
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/scala.lang.security.audit.rsa-padding-set.rsa-padding-set
shortlink: https://sg.run/GO5p
semgrep.dev:
rule:
r_id: 15192
rv_id: 1263677
rule_id: 3qUj1Q
version_id: yeTxpoX
url: https://semgrep.dev/playground/r/yeTxpoX/scala.lang.security.audit.rsa-padding-set.rsa-padding-set
origin: community
message: Usage of RSA without OAEP (Optimal Asymmetric Encryption Padding) may weaken
encryption. This could lead to sensitive data exposure. Instead, use RSA with
`OAEPWithMD5AndMGF1Padding` instead.
severity: WARNING
languages:
- scala
patterns:
- pattern: |
$VAR = $CIPHER.getInstance($MODE)
- metavariable-regex:
metavariable: $MODE
regex: .*RSA/.*/NoPadding.*
- id: typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption
message: 'Add "encryption: $Y.BucketEncryption.KMS_MANAGED" or "encryption: $Y.BucketEncryption.S3_MANAGED"
to the bucket props for Bucket construct $X'
metadata:
cwe:
- 'CWE-311: Missing Encryption of Sensitive Data'
category: security
technology:
- AWS-CDK
references:
- https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html
owasp:
- A03:2017 - Sensitive Data Exposure
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption
shortlink: https://sg.run/eowX
semgrep.dev:
rule:
r_id: 15276
rv_id: 1263903
rule_id: bwU8qz
version_id: GxTkeRx
url: https://semgrep.dev/playground/r/GxTkeRx/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption
origin: community
languages:
- typescript
severity: ERROR
pattern-either:
- patterns:
- pattern-inside: |
import {Bucket} from '@aws-cdk/aws-s3'
...
- pattern: const $X = new Bucket(...)
- pattern-not: |
const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS_MANAGED, ...})
- pattern-not: |
const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS, ...})
- pattern-not: |
const $X = new Bucket(..., {..., encryption: BucketEncryption.S3_MANAGED, ...})
- patterns:
- pattern-inside: |
import * as $Y from '@aws-cdk/aws-s3'
...
- pattern: const $X = new $Y.Bucket(...)
- pattern-not: |
const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS_MANAGED, ...})
- pattern-not: |
const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS, ...})
- pattern-not: |
const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.S3_MANAGED, ...})
- id: typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl
message: Bucket $X is not set to enforce encryption-in-transit, if not explictly
setting this on the bucket policy - the property "enforceSSL" should be set to
true
metadata:
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
category: security
technology:
- AWS-CDK
references:
- https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl
shortlink: https://sg.run/vqBX
semgrep.dev:
rule:
r_id: 15277
rv_id: 1263904
rule_id: NbUN8B
version_id: RGT0Llg
url: https://semgrep.dev/playground/r/RGT0Llg/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl
origin: community
languages:
- ts
severity: ERROR
pattern-either:
- patterns:
- pattern-inside: |
import {Bucket} from '@aws-cdk/aws-s3';
...
- pattern: const $X = new Bucket(...)
- pattern-not: |
const $X = new Bucket(..., {enforceSSL: true}, ...)
- patterns:
- pattern-inside: |
import * as $Y from '@aws-cdk/aws-s3';
...
- pattern: const $X = new $Y.Bucket(...)
- pattern-not: |
const $X = new $Y.Bucket(..., {..., enforceSSL: true, ...})
- id: typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue
message: 'Queue $X is missing encryption at rest. Add "encryption: $Y.QueueEncryption.KMS"
or "encryption: $Y.QueueEncryption.KMS_MANAGED" to the queue props to enable encryption
at rest for the queue.'
metadata:
category: security
cwe:
- 'CWE-311: Missing Encryption of Sensitive Data'
technology:
- AWS-CDK
references:
- https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-data-protection.html
owasp:
- A03:2017 - Sensitive Data Exposure
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue
shortlink: https://sg.run/d23P
semgrep.dev:
rule:
r_id: 15278
rv_id: 1263905
rule_id: kxUwqO
version_id: A8Tgd2W
url: https://semgrep.dev/playground/r/A8Tgd2W/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue
origin: community
languages:
- ts
severity: WARNING
pattern-either:
- patterns:
- pattern-inside: |
import {Queue} from '@aws-cdk/aws-sqs'
...
- pattern: const $X = new Queue(...)
- pattern-not: |
const $X = new Queue(..., {..., encryption: QueueEncryption.KMS_MANAGED, ...})
- pattern-not: |
const $X = new Queue(..., {..., encryption: QueueEncryption.KMS, ...})
- patterns:
- pattern-inside: |
import * as $Y from '@aws-cdk/aws-sqs'
...
- pattern: const $X = new $Y.Queue(...)
- pattern-not: |
const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS_MANAGED, ...})
- pattern-not: |
const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS, ...})
- id: typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod
message: Using the GrantPublicAccess method on bucket contruct $X will make the
objects in the bucket world accessible. Verify if this is intentional.
metadata:
cwe:
- 'CWE-306: Missing Authentication for Critical Function'
category: security
technology:
- AWS-CDK
references:
- https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-overview.html
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod
shortlink: https://sg.run/Z4p7
semgrep.dev:
rule:
r_id: 15279
rv_id: 1263906
rule_id: wdUjZK
version_id: BjTkZA7
url: https://semgrep.dev/playground/r/BjTkZA7/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod
origin: community
languages:
- ts
severity: WARNING
pattern-either:
- patterns:
- pattern-inside: |
import {Bucket} from '@aws-cdk/aws-s3'
...
- pattern: |
const $X = new Bucket(...)
...
$X.grantPublicAccess(...)
- patterns:
- pattern-inside: |
import * as $Y from '@aws-cdk/aws-s3'
...
- pattern: |
const $X = new $Y.Bucket(...)
...
$X.grantPublicAccess(...)
- id: typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public
message: CodeBuild Project $X is set to have a public URL. This will make the build
results, logs, artifacts publically accessible, including builds prior to the
project being public. Ensure this is acceptable for the project.
metadata:
category: security
cwe:
- 'CWE-306: Missing Authentication for Critical Function'
technology:
- AWS-CDK
references:
- https://docs.aws.amazon.com/codebuild/latest/userguide/public-builds.html
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public
shortlink: https://sg.run/nK7G
semgrep.dev:
rule:
r_id: 15280
rv_id: 1263907
rule_id: x8UxXZ
version_id: DkTRbj1
url: https://semgrep.dev/playground/r/DkTRbj1/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public
origin: community
languages:
- ts
severity: WARNING
pattern-either:
- patterns:
- pattern-inside: |
import {Project} from '@aws-cdk/aws-codebuild'
...
- pattern: |
const $X = new Project(..., {..., badge: true, ...})
- patterns:
- pattern-inside: |
import * as $Y from '@aws-cdk/aws-codebuild'
...
- pattern: |
const $X = new $Y.Project(..., {..., badge: true, ...})
- id: python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text
mode: taint
pattern-sinks:
- pattern: |
sqlalchemy.text(...)
pattern-sources:
- patterns:
- pattern: |
$X + $Y
- metavariable-type:
metavariable: $X
type: string
- patterns:
- pattern: |
$X + $Y
- metavariable-type:
metavariable: $Y
type: string
- patterns:
- pattern: |
f"..."
- patterns:
- pattern: |
$X.format(...)
- metavariable-type:
metavariable: $X
type: string
- patterns:
- pattern: |
$X % $Y
- metavariable-type:
metavariable: $X
type: string
message: sqlalchemy.text passes the constructed SQL statement to the database mostly
unchanged. This means that the usual SQL injection protections are not applied
and this function is vulnerable to SQL injection if user input can reach here.
Use normal SQLAlchemy operators (such as `or_()`, `and_()`, etc.) to construct
SQL.
metadata:
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
category: security
technology:
- sqlalchemy
confidence: MEDIUM
references:
- https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text
shortlink: https://sg.run/yP1O
semgrep.dev:
rule:
r_id: 15824
rv_id: 1263577
rule_id: r6U2wE
version_id: rxTAKqq
url: https://semgrep.dev/playground/r/rxTAKqq/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text
origin: community
languages:
- python
severity: ERROR
- id: terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code
pattern-either:
- patterns:
- pattern: password = "..."
- pattern-inside: |
resource "aws_db_instance" "..." {
...
}
- patterns:
- pattern: master_password = "..."
- pattern-inside: |
resource "aws_rds_cluster" "..." {
...
}
languages:
- hcl
severity: WARNING
message: RDS instance or cluster with hardcoded credentials in source code. It is
recommended to pass the credentials at runtime, or generate random credentials
using the random_password resource.
metadata:
references:
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/db_instance#master_password
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/rds_cluster#master_password
- https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/password
cwe:
- 'CWE-522: Insufficiently Protected Credentials'
category: security
technology:
- terraform
- aws
- secrets
owasp:
- A02:2017 - Broken Authentication
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code
shortlink: https://sg.run/x4qA
semgrep.dev:
rule:
r_id: 15830
rv_id: 1263896
rule_id: OrUl6W
version_id: gETB77b
url: https://semgrep.dev/playground/r/gETB77b/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code
origin: community
- id: generic.ci.security.bash-reverse-shell.bash_reverse_shell
metadata:
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
category: security
technology:
- ci
confidence: HIGH
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
subcategory:
- audit
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/generic.ci.security.bash-reverse-shell.bash_reverse_shell
shortlink: https://sg.run/4l9l
semgrep.dev:
rule:
r_id: 16200
rv_id: 1262664
rule_id: gxUJrJ
version_id: jQTn5QE
url: https://semgrep.dev/playground/r/jQTn5QE/generic.ci.security.bash-reverse-shell.bash_reverse_shell
origin: community
message: Semgrep found a bash reverse shell
severity: ERROR
languages:
- generic
pattern-either:
- pattern: |
sh -i >& /dev/udp/.../... 0>&1
- pattern: |
<...>/dev/tcp/.../...; sh <&... >&... 2>&
- pattern: |
<...>/dev/tcp/.../...; cat <&... | while read line; do $line 2>&... >&...;done
- pattern: |
sh -i ...<...> /dev/tcp/.../... ...<&... 1>&... 2>&
- id: terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket
patterns:
- pattern: a
- pattern: b
languages:
- hcl
severity: INFO
message: This rule has been deprecated, as all s3 buckets are encrypted by default
with no way to disable it. See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket_server_side_encryption_configuration
for more info.
metadata:
references:
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#server_side_encryption_configuration
- https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-encryption.html
cwe:
- 'CWE-311: Missing Encryption of Sensitive Data'
category: security
technology:
- terraform
- aws
owasp:
- A03:2017 - Sensitive Data Exposure
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
deprecated: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket
shortlink: https://sg.run/Jezw
semgrep.dev:
rule:
r_id: 16202
rv_id: 1263901
rule_id: 3qU62L
version_id: JdTzxjN
url: https://semgrep.dev/playground/r/JdTzxjN/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket
origin: community
- id: php.lang.security.injection.tainted-filename.tainted-filename
severity: WARNING
message: File name based on user input risks server-side request forgery.
metadata:
technology:
- php
category: security
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
references:
- https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/php.lang.security.injection.tainted-filename.tainted-filename
shortlink: https://sg.run/Ayqp
semgrep.dev:
rule:
r_id: 16250
rv_id: 1263287
rule_id: 5rUpro
version_id: 7ZTE3J1
url: https://semgrep.dev/playground/r/7ZTE3J1/php.lang.security.injection.tainted-filename.tainted-filename
origin: community
languages:
- php
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: $_GET
- pattern: $_POST
- pattern: $_COOKIE
- pattern: $_REQUEST
- pattern: $_SERVER
pattern-sanitizers:
- patterns:
- pattern-either:
- pattern-inside: basename($PATH, ...)
- pattern-inside: linkinfo($PATH, ...)
- pattern-inside: readlink($PATH, ...)
- pattern-inside: realpath($PATH, ...)
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: opcache_compile_file($FILENAME, ...)
- pattern-inside: opcache_invalidate($FILENAME, ...)
- pattern-inside: opcache_is_script_cached($FILENAME, ...)
- pattern-inside: runkit7_import($FILENAME, ...)
- pattern-inside: readline_read_history($FILENAME, ...)
- pattern-inside: readline_write_history($FILENAME, ...)
- pattern-inside: rar_open($FILENAME, ...)
- pattern-inside: zip_open($FILENAME, ...)
- pattern-inside: gzfile($FILENAME, ...)
- pattern-inside: gzopen($FILENAME, ...)
- pattern-inside: readgzfile($FILENAME, ...)
- pattern-inside: hash_file($ALGO, $FILENAME, ...)
- pattern-inside: hash_update_file($CONTEXT, $FILENAME, ...)
- pattern-inside: pg_trace($FILENAME, ...)
- pattern-inside: dio_open($FILENAME, ...)
- pattern-inside: finfo_file($FINFO, $FILENAME, ...)
- pattern-inside: mime_content_type($FILENAME, ...)
- pattern-inside: chgrp($FILENAME, ...)
- pattern-inside: chmod($FILENAME, ...)
- pattern-inside: chown($FILENAME, ...)
- pattern-inside: clearstatcache($CLEAR_REALPATH_CACHE, $FILENAME, ...)
- pattern-inside: file_exists($FILENAME, ...)
- pattern-inside: file_get_contents($FILENAME, ...)
- pattern-inside: file_put_contents($FILENAME, ...)
- pattern-inside: file($FILENAME, ...)
- pattern-inside: fileatime($FILENAME, ...)
- pattern-inside: filectime($FILENAME, ...)
- pattern-inside: filegroup($FILENAME, ...)
- pattern-inside: fileinode($FILENAME, ...)
- pattern-inside: filemtime($FILENAME, ...)
- pattern-inside: fileowner($FILENAME, ...)
- pattern-inside: fileperms($FILENAME, ...)
- pattern-inside: filesize($FILENAME, ...)
- pattern-inside: filetype($FILENAME, ...)
- pattern-inside: fnmatch($PATTERN, $FILENAME, ...)
- pattern-inside: fopen($FILENAME, ...)
- pattern-inside: is_dir($FILENAME, ...)
- pattern-inside: is_executable($FILENAME, ...)
- pattern-inside: is_file($FILENAME, ...)
- pattern-inside: is_link($FILENAME, ...)
- pattern-inside: is_readable($FILENAME, ...)
- pattern-inside: is_uploaded_file($FILENAME, ...)
- pattern-inside: is_writable($FILENAME, ...)
- pattern-inside: lchgrp($FILENAME, ...)
- pattern-inside: lchown($FILENAME, ...)
- pattern-inside: lstat($FILENAME, ...)
- pattern-inside: parse_ini_file($FILENAME, ...)
- pattern-inside: readfile($FILENAME, ...)
- pattern-inside: stat($FILENAME, ...)
- pattern-inside: touch($FILENAME, ...)
- pattern-inside: unlink($FILENAME, ...)
- pattern-inside: xattr_get($FILENAME, ...)
- pattern-inside: xattr_list($FILENAME, ...)
- pattern-inside: xattr_remove($FILENAME, ...)
- pattern-inside: xattr_set($FILENAME, ...)
- pattern-inside: xattr_supported($FILENAME, ...)
- pattern-inside: enchant_broker_request_pwl_dict($BROKER, $FILENAME, ...)
- pattern-inside: pspell_config_personal($CONFIG, $FILENAME, ...)
- pattern-inside: pspell_config_repl($CONFIG, $FILENAME, ...)
- pattern-inside: pspell_new_personal($FILENAME, ...)
- pattern-inside: exif_imagetype($FILENAME, ...)
- pattern-inside: getimagesize($FILENAME, ...)
- pattern-inside: image2wbmp($IMAGE, $FILENAME, ...)
- pattern-inside: imagecreatefromavif($FILENAME, ...)
- pattern-inside: imagecreatefrombmp($FILENAME, ...)
- pattern-inside: imagecreatefromgd2($FILENAME, ...)
- pattern-inside: imagecreatefromgd2part($FILENAME, ...)
- pattern-inside: imagecreatefromgd($FILENAME, ...)
- pattern-inside: imagecreatefromgif($FILENAME, ...)
- pattern-inside: imagecreatefromjpeg($FILENAME, ...)
- pattern-inside: imagecreatefrompng($FILENAME, ...)
- pattern-inside: imagecreatefromtga($FILENAME, ...)
- pattern-inside: imagecreatefromwbmp($FILENAME, ...)
- pattern-inside: imagecreatefromwebp($FILENAME, ...)
- pattern-inside: imagecreatefromxbm($FILENAME, ...)
- pattern-inside: imagecreatefromxpm($FILENAME, ...)
- pattern-inside: imageloadfont($FILENAME, ...)
- pattern-inside: imagexbm($IMAGE, $FILENAME, ...)
- pattern-inside: iptcembed($IPTC_DATA, $FILENAME, ...)
- pattern-inside: mailparse_msg_extract_part_file($MIMEMAIL, $FILENAME, ...)
- pattern-inside: mailparse_msg_extract_whole_part_file($MIMEMAIL, $FILENAME,
...)
- pattern-inside: mailparse_msg_parse_file($FILENAME, ...)
- pattern-inside: fdf_add_template($FDF_DOCUMENT, $NEWPAGE, $FILENAME, ...)
- pattern-inside: fdf_get_ap($FDF_DOCUMENT, $FIELD, $FACE, $FILENAME, ...)
- pattern-inside: fdf_open($FILENAME, ...)
- pattern-inside: fdf_save($FDF_DOCUMENT, $FILENAME, ...)
- pattern-inside: fdf_set_ap($FDF_DOCUMENT, $FIELD_NAME, $FACE, $FILENAME, ...)
- pattern-inside: ps_add_launchlink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME,
...)
- pattern-inside: ps_add_pdflink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME,
...)
- pattern-inside: ps_open_file($PSDOC, $FILENAME, ...)
- pattern-inside: ps_open_image_file($PSDOC, $TYPE, $FILENAME, ...)
- pattern-inside: posix_access($FILENAME, ...)
- pattern-inside: posix_mkfifo($FILENAME, ...)
- pattern-inside: posix_mknod($FILENAME, ...)
- pattern-inside: ftok($FILENAME, ...)
- pattern-inside: fann_cascadetrain_on_file($ANN, $FILENAME, ...)
- pattern-inside: fann_read_train_from_file($FILENAME, ...)
- pattern-inside: fann_train_on_file($ANN, $FILENAME, ...)
- pattern-inside: highlight_file($FILENAME, ...)
- pattern-inside: php_strip_whitespace($FILENAME, ...)
- pattern-inside: stream_resolve_include_path($FILENAME, ...)
- pattern-inside: swoole_async_read($FILENAME, ...)
- pattern-inside: swoole_async_readfile($FILENAME, ...)
- pattern-inside: swoole_async_write($FILENAME, ...)
- pattern-inside: swoole_async_writefile($FILENAME, ...)
- pattern-inside: swoole_load_module($FILENAME, ...)
- pattern-inside: tidy_parse_file($FILENAME, ...)
- pattern-inside: tidy_repair_file($FILENAME, ...)
- pattern-inside: get_meta_tags($FILENAME, ...)
- pattern-inside: yaml_emit_file($FILENAME, ...)
- pattern-inside: yaml_parse_file($FILENAME, ...)
- pattern-inside: curl_file_create($FILENAME, ...)
- pattern-inside: ftp_chmod($FTP, $PERMISSIONS, $FILENAME, ...)
- pattern-inside: ftp_delete($FTP, $FILENAME, ...)
- pattern-inside: ftp_mdtm($FTP, $FILENAME, ...)
- pattern-inside: ftp_size($FTP, $FILENAME, ...)
- pattern-inside: rrd_create($FILENAME, ...)
- pattern-inside: rrd_fetch($FILENAME, ...)
- pattern-inside: rrd_graph($FILENAME, ...)
- pattern-inside: rrd_info($FILENAME, ...)
- pattern-inside: rrd_last($FILENAME, ...)
- pattern-inside: rrd_lastupdate($FILENAME, ...)
- pattern-inside: rrd_tune($FILENAME, ...)
- pattern-inside: rrd_update($FILENAME, ...)
- pattern-inside: snmp_read_mib($FILENAME, ...)
- pattern-inside: ssh2_sftp_chmod($SFTP, $FILENAME, ...)
- pattern-inside: ssh2_sftp_realpath($SFTP, $FILENAME, ...)
- pattern-inside: ssh2_sftp_unlink($SFTP, $FILENAME, ...)
- pattern-inside: apache_lookup_uri($FILENAME, ...)
- pattern-inside: md5_file($FILENAME, ...)
- pattern-inside: sha1_file($FILENAME, ...)
- pattern-inside: simplexml_load_file($FILENAME, ...)
- pattern: $FILENAME
- id: php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation
languages:
- php
severity: WARNING
message: <- A new object is created where the class name is based on user input.
This could lead to remote code execution, as it allows to instantiate any class
in the application.
metadata:
cwe:
- 'CWE-470: Use of Externally-Controlled Input to Select Classes or Code (''Unsafe
Reflection'')'
category: security
technology:
- php
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation
shortlink: https://sg.run/7ndw
semgrep.dev:
rule:
r_id: 16438
rv_id: 1263288
rule_id: v8U4DA
version_id: LjTkgLy
url: https://semgrep.dev/playground/r/LjTkgLy/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: $_GET
- pattern: $_POST
- pattern: $_COOKIE
- pattern: $_REQUEST
- pattern: $_SERVER
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: new $SINK(...)
- pattern: $SINK
- id: terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials
patterns:
- pattern-inside: |
provider "aws" {
...
secret_key = "$SECRET"
}
- focus-metavariable: $SECRET
message: A hard-coded credential was detected. It is not recommended to store credentials
in source-code, as this risks secrets being leaked and used by either an internal
or external malicious adversary. It is recommended to use environment variables
to securely provide credentials or retrieve credentials from a secure vault or
HSM (Hardware Security Module).
languages:
- hcl
severity: WARNING
metadata:
technology:
- secrets
- aws
- terraform
category: security
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials
shortlink: https://sg.run/L3kn
semgrep.dev:
rule:
r_id: 16439
rv_id: 1263735
rule_id: d8U4n0
version_id: rxTAK76
url: https://semgrep.dev/playground/r/rxTAK76/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials
origin: community
- id: php.laravel.security.laravel-sql-injection.laravel-sql-injection
metadata:
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
category: security
technology:
- laravel
references:
- https://laravel.com/docs/8.x/queries
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/php.laravel.security.laravel-sql-injection.laravel-sql-injection
shortlink: https://sg.run/x40p
semgrep.dev:
rule:
r_id: 16830
rv_id: 1263313
rule_id: j2UQdp
version_id: BjTkZ45
url: https://semgrep.dev/playground/r/BjTkZ45/php.laravel.security.laravel-sql-injection.laravel-sql-injection
origin: community
severity: WARNING
message: Detected a SQL query based on user input. This could lead to SQL injection,
which could potentially result in sensitive data being exfiltrated by attackers.
Instead, use parameterized queries and prepared statements.
languages:
- php
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: $_GET
- pattern: $_POST
- pattern: $_COOKIE
- pattern: $_REQUEST
- pattern: $_SERVER
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: $SQL
- pattern-either:
- pattern-inside: DB::table(...)->whereRaw($SQL, ...)
- pattern-inside: DB::table(...)->orWhereRaw($SQL, ...)
- pattern-inside: DB::table(...)->groupByRaw($SQL, ...)
- pattern-inside: DB::table(...)->havingRaw($SQL, ...)
- pattern-inside: DB::table(...)->orHavingRaw($SQL, ...)
- pattern-inside: DB::table(...)->orderByRaw($SQL, ...)
- patterns:
- pattern: $EXPRESSION
- pattern-either:
- pattern-inside: DB::table(...)->selectRaw($EXPRESSION, ...)
- pattern-inside: DB::table(...)->fromRaw($EXPRESSION, ...)
- patterns:
- pattern: $COLUMNS
- pattern-either:
- pattern-inside: DB::table(...)->whereNull($COLUMNS, ...)
- pattern-inside: DB::table(...)->orWhereNull($COLUMN)
- pattern-inside: DB::table(...)->whereNotNull($COLUMNS, ...)
- pattern-inside: DB::table(...)->whereRowValues($COLUMNS, ...)
- pattern-inside: DB::table(...)->orWhereRowValues($COLUMNS, ...)
- pattern-inside: DB::table(...)->find($ID, $COLUMNS)
- pattern-inside: DB::table(...)->paginate($PERPAGE, $COLUMNS, ...)
- pattern-inside: DB::table(...)->simplePaginate($PERPAGE, $COLUMNS, ...)
- pattern-inside: DB::table(...)->cursorPaginate($PERPAGE, $COLUMNS, ...)
- pattern-inside: DB::table(...)->getCountForPagination($COLUMNS)
- pattern-inside: DB::table(...)->aggregate($FUNCTION, $COLUMNS)
- pattern-inside: DB::table(...)->numericAggregate($FUNCTION, $COLUMNS)
- pattern-inside: DB::table(...)->insertUsing($COLUMNS, ...)
- pattern-inside: DB::table(...)->select($COLUMNS)
- pattern-inside: DB::table(...)->get($COLUMNS)
- pattern-inside: DB::table(...)->count($COLUMNS)
- patterns:
- pattern: $COLUMN
- pattern-either:
- pattern-inside: DB::table(...)->whereIn($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereIn($COLUMN, ...)
- pattern-inside: DB::table(...)->whereNotIn($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereNotIn($COLUMN, ...)
- pattern-inside: DB::table(...)->whereIntegerInRaw($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereIntegerInRaw($COLUMN, ...)
- pattern-inside: DB::table(...)->whereIntegerNotInRaw($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereIntegerNotInRaw($COLUMN, ...)
- pattern-inside: DB::table(...)->whereBetweenColumns($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereBetween($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereBetweenColumns($COLUMN, ...)
- pattern-inside: DB::table(...)->whereNotBetween($COLUMN, ...)
- pattern-inside: DB::table(...)->whereNotBetweenColumns($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereNotBetween($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereNotBetweenColumns($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereNotNull($COLUMN)
- pattern-inside: DB::table(...)->whereDate($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereDate($COLUMN, ...)
- pattern-inside: DB::table(...)->whereTime($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereTime($COLUMN, ...)
- pattern-inside: DB::table(...)->whereDay($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereDay($COLUMN, ...)
- pattern-inside: DB::table(...)->whereMonth($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereMonth($COLUMN, ...)
- pattern-inside: DB::table(...)->whereYear($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereYear($COLUMN, ...)
- pattern-inside: DB::table(...)->whereJsonContains($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereJsonContains($COLUMN, ...)
- pattern-inside: DB::table(...)->whereJsonDoesntContain($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereJsonDoesntContain($COLUMN, ...)
- pattern-inside: DB::table(...)->whereJsonLength($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhereJsonLength($COLUMN, ...)
- pattern-inside: DB::table(...)->having($COLUMN, ...)
- pattern-inside: DB::table(...)->orHaving($COLUMN, ...)
- pattern-inside: DB::table(...)->havingBetween($COLUMN, ...)
- pattern-inside: DB::table(...)->orderBy($COLUMN, ...)
- pattern-inside: DB::table(...)->orderByDesc($COLUMN)
- pattern-inside: DB::table(...)->latest($COLUMN)
- pattern-inside: DB::table(...)->oldest($COLUMN)
- pattern-inside: DB::table(...)->forPageBeforeId($PERPAGE, $LASTID, $COLUMN)
- pattern-inside: DB::table(...)->forPageAfterId($PERPAGE, $LASTID, $COLUMN)
- pattern-inside: DB::table(...)->value($COLUMN)
- pattern-inside: DB::table(...)->pluck($COLUMN, ...)
- pattern-inside: DB::table(...)->implode($COLUMN, ...)
- pattern-inside: DB::table(...)->min($COLUMN)
- pattern-inside: DB::table(...)->max($COLUMN)
- pattern-inside: DB::table(...)->sum($COLUMN)
- pattern-inside: DB::table(...)->avg($COLUMN)
- pattern-inside: DB::table(...)->average($COLUMN)
- pattern-inside: DB::table(...)->increment($COLUMN, ...)
- pattern-inside: DB::table(...)->decrement($COLUMN, ...)
- pattern-inside: DB::table(...)->where($COLUMN, ...)
- pattern-inside: DB::table(...)->orWhere($COLUMN, ...)
- pattern-inside: DB::table(...)->addSelect($COLUMN)
- patterns:
- pattern: $QUERY
- pattern-inside: DB::unprepared($QUERY)
- id: java.lang.security.audit.crypto.use-of-md5.use-of-md5
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
resistant and is therefore not suitable as a cryptographic signature. Use HMAC
instead.
languages:
- java
severity: WARNING
metadata:
functional-categories:
- crypto::search::hash-algorithm::java.security
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-328: Use of Weak Hash'
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5.use-of-md5
shortlink: https://sg.run/ryJn
semgrep.dev:
rule:
r_id: 17325
rv_id: 1263013
rule_id: KxU5lW
version_id: 0bTKzGX
url: https://semgrep.dev/playground/r/0bTKzGX/java.lang.security.audit.crypto.use-of-md5.use-of-md5
origin: community
patterns:
- pattern: |
java.security.MessageDigest.getInstance($ALGO, ...);
- metavariable-regex:
metavariable: $ALGO
regex: (?i)(.MD5.)
- focus-metavariable: $ALGO
fix: |
"SHA-512"
- id: java.lang.security.audit.crypto.use-of-sha1.use-of-sha1
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
collision resistant and is therefore not suitable as a cryptographic signature.
Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function
applications.
languages:
- java
severity: WARNING
metadata:
functional-categories:
- crypto::search::hash-algorithm::javax.crypto
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-328: Use of Weak Hash'
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1
shortlink: https://sg.run/bXNp
semgrep.dev:
rule:
r_id: 17326
rv_id: 1263016
rule_id: qNUWNn
version_id: l4TJRpL
url: https://semgrep.dev/playground/r/l4TJRpL/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1
origin: community
pattern-either:
- patterns:
- pattern: |
java.security.MessageDigest.getInstance("$ALGO", ...);
- metavariable-regex:
metavariable: $ALGO
regex: (SHA1|SHA-1)
- pattern: |
$DU.getSha1Digest().digest(...)
- id: terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version
patterns:
- pattern: |
resource "aws_cloudfront_distribution" $ANYTHING {
...
viewer_certificate {
...
}
...
}
- pattern-not-inside: |
resource "aws_cloudfront_distribution" $ANYTHING {
...
viewer_certificate {
...
minimum_protocol_version = "TLSv1.2_2018"
...
}
...
}
- pattern-not-inside: |
resource "aws_cloudfront_distribution" $ANYTHING {
...
viewer_certificate {
...
minimum_protocol_version = "TLSv1.2_2019"
...
}
...
}
- pattern-not-inside: |
resource "aws_cloudfront_distribution" $ANYTHING {
...
viewer_certificate {
...
minimum_protocol_version = "TLSv1.2_2021"
...
}
...
}
- pattern-not-inside: |
resource "aws_cloudfront_distribution" $ANYTHING {
...
viewer_certificate {
...
minimum_protocol_version = "TLSv1.2_2025"
...
}
...
}
- pattern-not-inside: |
resource "aws_cloudfront_distribution" $ANYTHING {
...
viewer_certificate {
...
minimum_protocol_version = "TLSv1.3_2025"
...
}
...
}
message: Detected an AWS CloudFront Distribution with an insecure TLS version. TLS
versions less than 1.2 are considered insecure because they can be broken. To
fix this, set your `minimum_protocol_version` to `"TLSv1.2_2018", "TLSv1.2_2019",
"TLSv1.2_2021", "TLSv1.2_2025" or "TLSv1.3_2025"`.
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version
shortlink: https://sg.run/Q6o4
semgrep.dev:
rule:
r_id: 17342
rv_id: 1263700
rule_id: kxU6A8
version_id: 5PTo1bY
url: https://semgrep.dev/playground/r/5PTo1bY/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention
patterns:
- pattern: |
resource "aws_cloudwatch_log_group" $ANYTHING {
...
}
- pattern-not-inside: |
resource "aws_cloudwatch_log_group" $ANYTHING {
...
retention_in_days = ...
...
}
message: The AWS CloudWatch Log Group has no retention. Missing retention in log
groups can cause losing important event information.
languages:
- hcl
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
cwe:
- 'CWE-320: CWE CATEGORY: Key Management Errors'
technology:
- aws
- terraform
category: security
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention
shortlink: https://sg.run/4lwl
semgrep.dev:
rule:
r_id: 17344
rv_id: 946665
rule_id: x8UGBG
version_id: BjT1N2B
url: https://semgrep.dev/playground/r/BjT1N2B/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention
origin: community
- id: terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted
patterns:
- pattern: |
resource "aws_codebuild_project" $ANYTHING {
...
}
- pattern-not-inside: |
resource "aws_codebuild_project" $ANYTHING {
...
encryption_key = ...
...
}
message: The AWS CodeBuild Project is unencrypted. The AWS KMS encryption key protects
projects in the CodeBuild. To create your own, create a aws_kms_key resource or
use the ARN string of a key in your account.
languages:
- hcl
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
cwe:
- 'CWE-320: CWE CATEGORY: Key Management Errors'
technology:
- aws
- terraform
category: security
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted
shortlink: https://sg.run/5yxA
semgrep.dev:
rule:
r_id: 17347
rv_id: 946669
rule_id: v8U4kG
version_id: K3TJbNr
url: https://semgrep.dev/playground/r/K3TJbNr/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted
origin: community
- id: terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging
patterns:
- pattern: |
resource "aws_db_instance" $ANYTHING {
...
}
- pattern-not-inside: |
resource "aws_db_instance" $ANYTHING {
...
enabled_cloudwatch_logs_exports = [$SOMETHING, ...]
...
}
message: Database instance has no logging. Missing logs can cause missing important
event information.
languages:
- hcl
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
cwe:
- 'CWE-311: Missing Encryption of Sensitive Data'
technology:
- aws
- terraform
category: security
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
subcategory:
- vuln
likelihood: MEDIUM
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging
shortlink: https://sg.run/GyAp
semgrep.dev:
rule:
r_id: 17348
rv_id: 1263704
rule_id: d8U4RA
version_id: BjTkZ6j
url: https://semgrep.dev/playground/r/BjTkZ6j/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging
origin: community
- id: terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted
patterns:
- pattern: |
resource "aws_dynamodb_table" $ANYTHING {
...
}
- pattern-not-inside: |
resource "aws_dynamodb_table" $ANYTHING {
...
server_side_encryption {
enabled = true
kms_key_arn = ...
}
...
}
message: By default, AWS DynamoDB Table is encrypted using AWS-managed keys. However,
for added security, it's recommended to configure your own AWS KMS encryption
key to protect your data in the DynamoDB table. You can either create a new aws_kms_key
resource or use the ARN of an existing key in your AWS account to do so.
languages:
- hcl
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
technology:
- aws
- terraform
category: security
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted
shortlink: https://sg.run/Ay4p
semgrep.dev:
rule:
r_id: 17350
rv_id: 1263707
rule_id: nJUGe2
version_id: 0bTKzj8
url: https://semgrep.dev/playground/r/0bTKzj8/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted
origin: community
- id: terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk
patterns:
- pattern: |
resource "aws_ebs_snapshot_copy" $ANYTHING {
...
encrypted = true
...
}
- pattern-not-inside: |
resource "aws_ebs_snapshot_copy" $ANYTHING {
...
encrypted = true
kms_key_id = ...
...
}
message: Ensure EBS Snapshot is encrypted at rest using KMS CMKs. CMKs gives you
control over the encryption key in terms of access and rotation.
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A03:2017 - Sensitive Data Exposure
cwe:
- 'CWE-320: CWE CATEGORY: Key Management Errors'
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk
shortlink: https://sg.run/ByPW
semgrep.dev:
rule:
r_id: 17351
rv_id: 946677
rule_id: EwUqko
version_id: A8TJzb0
url: https://semgrep.dev/playground/r/A8TJzb0/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted
patterns:
- pattern: |
resource "aws_ebs_encryption_by_default" $ANYTHING {
...
enabled = false
...
}
message: The AWS EBS is unencrypted. The AWS EBS encryption protects data in the
EBS.
languages:
- hcl
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
cwe:
- 'CWE-320: CWE CATEGORY: Key Management Errors'
technology:
- aws
- terraform
category: security
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted
shortlink: https://sg.run/Dy5Y
semgrep.dev:
rule:
r_id: 17352
rv_id: 946678
rule_id: 7KUW7K
version_id: BjT1N2v
url: https://semgrep.dev/playground/r/BjT1N2v/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted
origin: community
- id: terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip
patterns:
- pattern-either:
- pattern: |
resource "aws_instance" $ANYTHING {
...
associate_public_ip_address = true
...
}
- pattern: |
resource "aws_launch_template" $ANYTHING {
...
network_interfaces {
...
associate_public_ip_address = true
...
}
...
}
message: EC2 instances should not have a public IP address attached in order to
block public access to the instances. To fix this, set your `associate_public_ip_address`
to `"false"`.
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-1220: Insufficient Granularity of Access Control'
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip
shortlink: https://sg.run/08rv
semgrep.dev:
rule:
r_id: 17354
rv_id: 1263709
rule_id: 8GUA2n
version_id: qkTR73G
url: https://semgrep.dev/playground/r/qkTR73G/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk
patterns:
- pattern: |
resource "aws_efs_file_system" $ANYTHING {
...
encrypted = true
...
}
- pattern-not-inside: |
resource "aws_efs_file_system" $ANYTHING {
...
encrypted = true
kms_key_id = ...
...
}
message: Ensure EFS filesystem is encrypted at rest using KMS CMKs. CMKs gives you
control over the encryption key in terms of access and rotation.
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A03:2017 - Sensitive Data Exposure
cwe:
- 'CWE-320: CWE CATEGORY: Key Management Errors'
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk
shortlink: https://sg.run/Kk07
semgrep.dev:
rule:
r_id: 17355
rv_id: 946690
rule_id: gxUJ4n
version_id: 2KTYbWy
url: https://semgrep.dev/playground/r/2KTYbWy/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled
patterns:
- pattern-either:
- pattern: |
resource "aws_elasticsearch_domain" $ANYTHING {
...
node_to_node_encryption {
...
enabled = false
...
}
...
}
- pattern: |
resource "aws_elasticsearch_domain" $ANYTHING {
...
cluster_config {
...
instance_count = $COUNT
...
}
}
- pattern-not-inside: |
resource "aws_elasticsearch_domain" $ANYTHING {
...
cluster_config {
...
instance_count = $COUNT
...
}
node_to_node_encryption {
...
enabled = true
...
}
}
- metavariable-comparison:
metavariable: $COUNT
comparison: $COUNT > 1
message: "Ensure all Elasticsearch has node-to-node encryption enabled.\t"
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled
shortlink: https://sg.run/lp3y
semgrep.dev:
rule:
r_id: 17357
rv_id: 1263719
rule_id: 3qU6J7
version_id: WrTqK0v
url: https://semgrep.dev/playground/r/WrTqK0v/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal
patterns:
- pattern-inside: |
resource "aws_glacier_vault" $ANYTHING {
...
}
- pattern: access_policy = "$STATEMENT"
- metavariable-pattern:
metavariable: $STATEMENT
language: json
patterns:
- pattern-inside: |
{..., "Effect": "Allow", ...}
- pattern-either:
- pattern: |
"Principal": "*"
- pattern: |
"Principal": {..., "AWS": "*", ...}
- pattern-inside: |
"Principal": {..., "AWS": ..., ...}
- pattern-regex: |
(^\"arn:aws:iam::\*:(.*)\"$)
message: 'Detected wildcard access granted to Glacier Vault. This means anyone within
your AWS account ID can perform actions on Glacier resources. Instead, limit to
a specific identity in your account, like this: `arn:aws:iam::<account_id>:<identity>`.'
metadata:
category: security
technology:
- aws
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe:
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
references:
- https://cwe.mitre.org/data/definitions/732.html
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal
shortlink: https://sg.run/XN9K
semgrep.dev:
rule:
r_id: 17364
rv_id: 1263723
rule_id: AbUeYK
version_id: l4TJRGB
url: https://semgrep.dev/playground/r/l4TJRGB/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal
origin: community
languages:
- hcl
severity: ERROR
- id: terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin
patterns:
- pattern-inside: |
resource "aws_ssoadmin_permission_set_inline_policy" $ANYTHING {
...
}
- pattern: inline_policy = "$STATEMENT"
- metavariable-pattern:
metavariable: $STATEMENT
language: json
patterns:
- pattern-not-inside: |
{..., "Effect": "Deny", ...}
- pattern-either:
- pattern: |
{..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...}
- pattern: |
{..., "Action": "*", "Resource": "*", ...}
- pattern: |
{..., "Action": "*", "Resource": [...], ...}
- pattern: |
{..., "Action": [...], "Resource": "*", ...}
message: Detected admin access granted in your policy. This means anyone with this
policy can perform administrative actions. Instead, limit actions and resources
to what you need according to least privilege.
metadata:
category: security
technology:
- aws
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe:
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
references:
- https://cwe.mitre.org/data/definitions/732.html
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin
shortlink: https://sg.run/jzgY
semgrep.dev:
rule:
r_id: 17365
rv_id: 1263724
rule_id: BYUzY5
version_id: YDTZe9q
url: https://semgrep.dev/playground/r/YDTZe9q/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin
origin: community
languages:
- hcl
severity: ERROR
- id: terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy
patterns:
- pattern-inside: |
resource "aws_iam_policy" $ANYTHING {
...
}
- pattern: policy = "$STATEMENT"
- metavariable-pattern:
metavariable: $STATEMENT
language: json
patterns:
- pattern-not-inside: |
{..., "Effect": "Deny", ...}
- pattern-either:
- pattern: |
{..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...}
- pattern: |
{..., "Action": "*", "Resource": "*", ...}
- pattern: |
{..., "Action": "*", "Resource": [...], ...}
- pattern: |
{..., "Action": [...], "Resource": "*", ...}
message: Detected admin access granted in your policy. This means anyone with this
policy can perform administrative actions. Instead, limit actions and resources
to what you need according to least privilege.
metadata:
category: security
technology:
- aws
- terraform
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe:
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
references:
- https://cwe.mitre.org/data/definitions/732.html
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy
shortlink: https://sg.run/1zbw
semgrep.dev:
rule:
r_id: 17366
rv_id: 1263725
rule_id: DbUx8l
version_id: 6xT29Pv
url: https://semgrep.dev/playground/r/6xT29Pv/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy
origin: community
languages:
- hcl
severity: ERROR
- id: terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration
patterns:
- pattern: |
resource "aws_redshift_parameter_group" $ANYTHING {
...
}
- pattern-not-inside: |
resource "aws_redshift_parameter_group" $ANYTHING {
...
parameter {
name = "require_ssl"
value = "true"
}
...
}
- pattern-not-inside: |
resource "aws_redshift_parameter_group" $ANYTHING {
...
parameter {
name = "require_ssl"
value = true
}
...
}
message: Detected an AWS Redshift configuration with a SSL disabled. To fix this,
set your `require_ssl` to `"true"`.
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration
shortlink: https://sg.run/yPYx
semgrep.dev:
rule:
r_id: 17368
rv_id: 1263727
rule_id: 0oUrOj
version_id: zyTb27A
url: https://semgrep.dev/playground/r/zyTb27A/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal
patterns:
- pattern-inside: |
resource "aws_kms_key" $ANYTHING {
...
}
- pattern: policy = "$STATEMENT"
- metavariable-pattern:
metavariable: $STATEMENT
language: json
patterns:
- pattern-not-inside: |
{..., "Effect": "Deny", ...}
- pattern-either:
- pattern: |
{..., "Principal": "*", "Action": "kms:*", "Resource": "*", ...}
- pattern: |
{..., "Principal": [..., "*", ...], "Action": "kms:*", "Resource": "*", ...}
- pattern: |
{..., "Principal": { "AWS": "*" }, "Action": "kms:*", "Resource": "*", ...}
- pattern: |
{..., "Principal": { "AWS": [..., "*", ...] }, "Action": "kms:*", "Resource": "*", ...}
message: Detected wildcard access granted in your KMS key. This means anyone with
this policy can perform administrative actions over the keys. Instead, limit principals,
actions and resources to what you need according to least privilege.
metadata:
category: security
technology:
- aws
- terraform
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe:
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
references:
- https://cwe.mitre.org/data/definitions/732.html
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal
shortlink: https://sg.run/Nwlp
semgrep.dev:
rule:
r_id: 17371
rv_id: 1263729
rule_id: lBUWPD
version_id: 2KTv2J4
url: https://semgrep.dev/playground/r/2KTv2J4/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal
origin: community
languages:
- hcl
severity: ERROR
- id: terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation
patterns:
- pattern-either:
- pattern: |
resource "aws_kms_key" $ANYTHING {
...
enable_key_rotation = false
...
}
- pattern: |
resource "aws_kms_key" $ANYTHING {
...
customer_master_key_spec = "SYMMETRIC_DEFAULT"
enable_key_rotation = false
...
}
- pattern: |
resource "aws_kms_key" $ANYTHING {
...
}
- pattern-not-inside: |
resource "aws_kms_key" $ANYTHING {
...
enable_key_rotation = true
...
}
- pattern-not-inside: |
resource "aws_kms_key" $ANYTHING {
...
customer_master_key_spec = "RSA_2096"
...
}
message: The AWS KMS has no rotation. Missing rotation can cause leaked key to be
used by attackers. To fix this, set a `enable_key_rotation`.
languages:
- hcl
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
technology:
- aws
- terraform
category: security
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation
shortlink: https://sg.run/kz47
semgrep.dev:
rule:
r_id: 17372
rv_id: 1263730
rule_id: PeU0L3
version_id: X0Tzy67
url: https://semgrep.dev/playground/r/X0Tzy67/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation
origin: community
- id: terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials
patterns:
- pattern-inside: |
resource "$ANYTING" $ANYTHING {
...
environment {
variables = {
...
}
}
...
}
- pattern-either:
- pattern-inside: |
AWS_ACCESS_KEY_ID = "$Y"
- pattern-regex: |
(?<![A-Z0-9])[A-Z0-9]{20}(?![A-Z0-9])
- pattern-inside: |
AWS_SECRET_ACCESS_KEY = "$Y"
- pattern-regex: |
(?<![A-Za-z0-9/+=])[A-Za-z0-9/+=]{40}(?![A-Za-z0-9/+=])
- focus-metavariable: $Y
message: A hard-coded credential was detected. It is not recommended to store credentials
in source-code, as this risks secrets being leaked and used by either an internal
or external malicious adversary. It is recommended to use environment variables
to securely provide credentials or retrieve credentials from a secure vault or
HSM (Hardware Security Module).
metadata:
category: security
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
technology:
- aws
- terraform
- secrets
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials
shortlink: https://sg.run/wZqY
semgrep.dev:
rule:
r_id: 17373
rv_id: 1263731
rule_id: JDU6gj
version_id: jQTn573
url: https://semgrep.dev/playground/r/jQTn573/terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials
origin: community
languages:
- hcl
severity: ERROR
- id: terraform.aws.security.aws-rds-backup-no-retention.aws-rds-backup-no-retention
patterns:
- pattern-either:
- pattern: |
resource "aws_rds_cluster" $ANYTHING {
...
backup_retention_period = 0
...
}
- pattern: |
resource "aws_db_instance" $ANYTHING {
...
backup_retention_period = 0
...
}
message: The AWS RDS has no retention. Missing retention can cause losing important
event information. To fix this, set a `backup_retention_period`.
languages:
- hcl
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
cwe:
- 'CWE-320: CWE CATEGORY: Key Management Errors'
technology:
- aws
- terraform
category: security
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-rds-backup-no-retention.aws-rds-backup-no-retention
shortlink: https://sg.run/OyYB
semgrep.dev:
rule:
r_id: 17375
rv_id: 946719
rule_id: GdUzwQ
version_id: GxTP0Lq
url: https://semgrep.dev/playground/r/GxTP0Lq/terraform.aws.security.aws-rds-backup-no-retention.aws-rds-backup-no-retention
origin: community
- id: csharp.dotnet.security.razor-template-injection.razor-template-injection
message: User-controllable string passed to Razor.Parse. This leads directly to
code execution in the context of the process.
severity: WARNING
metadata:
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
category: security
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
cwe2022-top25: true
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://clement.notin.org/blog/2020/04/15/Server-Side-Template-Injection-(SSTI)-in-ASP.NET-Razor/
subcategory:
- vuln
technology:
- .net
- razor
- asp
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/csharp.dotnet.security.razor-template-injection.razor-template-injection
shortlink: https://sg.run/oyj0
semgrep.dev:
rule:
r_id: 18216
rv_id: 1262621
rule_id: EwUr68
version_id: 1QTypdj
url: https://semgrep.dev/playground/r/1QTypdj/csharp.dotnet.security.razor-template-injection.razor-template-injection
origin: community
languages:
- csharp
mode: taint
pattern-sources:
- patterns:
- focus-metavariable: $ARG
- pattern-inside: |
public ActionResult $METHOD(..., string $ARG,...){...}
pattern-sinks:
- pattern: |
Razor.Parse(...)
pattern-sanitizers:
- not_conflicting: true
pattern: $F(...)
- id: csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation
severity: WARNING
languages:
- csharp
metadata:
cwe:
- 'CWE-295: Improper Certificate Validation'
owasp:
- A03:2017 - Sensitive Data Exposure
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
references:
- https://docs.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.issuernameregistry?view=netframework-4.8
category: security
technology:
- .net
confidence: MEDIUM
subcategory:
- vuln
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation
shortlink: https://sg.run/XZ6B
semgrep.dev:
rule:
r_id: 18220
rv_id: 1262629
rule_id: gxUy01
version_id: xyTjzGW
url: https://semgrep.dev/playground/r/xyTjzGW/csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation
origin: community
message: Validating certificates based on subject name is bad practice. Use the
X509Certificate2.Verify() method instead.
patterns:
- pattern-inside: |
using System.IdentityModel.Tokens;
...
- pattern-either:
- patterns:
- pattern-either:
- pattern-inside: |
X509SecurityToken $TOK = $RHS;
...
- pattern-inside: |
$T $M(..., X509SecurityToken $TOK, ...) {
...
}
- metavariable-pattern:
metavariable: $RHS
pattern-either:
- pattern: $T as X509SecurityToken
- pattern: new X509SecurityToken(...)
- patterns:
- pattern-either:
- pattern-inside: |
X509Certificate2 $CERT = new X509Certificate2(...);
...
- pattern-inside: |
$T $M(..., X509Certificate2 $CERT, ...) {
...
}
- pattern-inside: |
foreach (X509Certificate2 $CERT in $COLLECTION) {
...
}
- patterns:
- pattern-either:
- pattern: String.Equals($NAME, "...")
- pattern: String.Equals("...", $NAME)
- pattern: $NAME.Equals("...")
- pattern: $NAME == "..."
- pattern: $NAME != "..."
- pattern: |
"..." == $NAME
- pattern: |
"..." != $NAME
- metavariable-pattern:
metavariable: $NAME
pattern-either:
- pattern: $TOK.Certificate.SubjectName.Name
- pattern: $CERT.SubjectName.Name
- pattern: $CERT.GetNameInfo(...)
- id: csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine
mode: taint
pattern-sources:
- patterns:
- pattern: $A
- pattern-inside: |
Path.Combine(...,$A,...)
- pattern-inside: |
public $TYPE $M(...,$A,...){...}
- pattern-not-inside: |
<... Path.GetFileName($A) != $A ...>
pattern-sinks:
- patterns:
- focus-metavariable: $X
- pattern: |
File.$METHOD($X,...)
- metavariable-regex:
metavariable: $METHOD
regex: (?i)^(read|write)
pattern-sanitizers:
- pattern: |
Path.GetFileName(...)
- patterns:
- pattern-inside: |
$X = Path.GetFileName(...);
...
- pattern: $X
- patterns:
- pattern: $X
- pattern-inside: |
if(<... Path.GetFileName($X) != $X ...>){
...
throw new $EXCEPTION(...);
}
...
message: String argument $A is used to read or write data from a file via Path.Combine
without direct sanitization via Path.GetFileName. If the path is user-supplied
data this can lead to path traversal.
languages:
- csharp
severity: WARNING
metadata:
category: security
confidence: MEDIUM
references:
- https://www.praetorian.com/blog/pathcombine-security-issues-in-aspnet-applications/
- https://docs.microsoft.com/en-us/dotnet/api/system.io.path.combine?view=net-6.0#remarks
technology:
- .net
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine
shortlink: https://sg.run/1RvG
semgrep.dev:
rule:
r_id: 18222
rv_id: 1262632
rule_id: 3qU3bE
version_id: vdT0644
url: https://semgrep.dev/playground/r/vdT0644/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine
origin: community
- id: csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings
severity: WARNING
languages:
- C#
metadata:
cwe:
- 'CWE-706: Use of Incorrectly-Resolved Name or Reference'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://docs.microsoft.com/en-us/dotnet/api/system.net.httplistener?view=net-6.0
category: security
technology:
- .net
confidence: MEDIUM
subcategory:
- vuln
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings
shortlink: https://sg.run/9LJr
semgrep.dev:
rule:
r_id: 18223
rv_id: 1262633
rule_id: 4bUQ81
version_id: d6Tyx4K
url: https://semgrep.dev/playground/r/d6Tyx4K/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings
origin: community
message: The top level wildcard bindings $PREFIX leaves your application open to
security vulnerabilities and give attackers more control over where traffic is
routed. If you must use wildcards, consider using subdomain wildcard binding.
For example, you can use "*.asdf.gov" if you own all of "asdf.gov".
patterns:
- pattern-inside: |
using System.Net;
...
- pattern: $LISTENER.Prefixes.Add("$PREFIX")
- metavariable-regex:
metavariable: $PREFIX
regex: (http|https)://(\*|\+)(.[a-zA-Z]{2,})?:[0-9]+
- id: csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout
severity: WARNING
languages:
- C#
metadata:
cwe:
- 'CWE-1333: Inefficient Regular Expression Complexity'
owasp: A01:2017 - Injection
references:
- https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS
- https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.infinitematchtimeout
- https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0
category: security
technology:
- .net
confidence: MEDIUM
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Denial-of-Service (DoS)
source: https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout
shortlink: https://sg.run/NgRy
semgrep.dev:
rule:
r_id: 18227
rv_id: 945224
rule_id: GdUDBP
version_id: yeT0nDq
url: https://semgrep.dev/playground/r/yeT0nDq/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout
origin: community
message: 'Specifying the regex timeout leaves the system vulnerable to a regex-based
Denial of Service (DoS) attack. Consider setting the timeout to a short amount
of time like 2 or 3 seconds. If you are sure you need an infinite timeout, double
check that your context meets the conditions outlined in the "Notes to Callers"
section at the bottom of this page: https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0'
patterns:
- pattern-inside: |
using System.Text.RegularExpressions;
...
- pattern-either:
- pattern: new Regex(..., TimeSpan.InfiniteMatchTimeout)
- patterns:
- pattern: new Regex(..., TimeSpan.FromSeconds($TIME))
- metavariable-comparison:
metavariable: $TIME
comparison: $TIME > 5
- pattern: new Regex(..., TimeSpan.FromMinutes(...))
- pattern: new Regex(..., TimeSpan.FromHours(...))
- id: csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override
mode: taint
pattern-sources:
- patterns:
- focus-metavariable: $ARG
- pattern-inside: |
public $T $M(...,string $ARG,...){...}
pattern-sinks:
- patterns:
- pattern: |
$XMLDOCUMENT.$METHOD(...)
- pattern-inside: "XmlDocument $XMLDOCUMENT = new XmlDocument(...);\n...\n$XMLDOCUMENT.XmlResolver
= new XmlUrlResolver(...);\n... \n"
message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling
a string argument from a public method. Enabling Document Type Definition (DTD)
parsing may cause XML External Entity (XXE) injection if supplied with user-controllable
data.
languages:
- csharp
severity: WARNING
metadata:
category: security
references:
- https://www.jardinesoftware.net/2016/05/26/xxe-and-net/
- https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks
technology:
- .net
- xml
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
impact: MEDIUM
likelihood: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override
shortlink: https://sg.run/k98P
semgrep.dev:
rule:
r_id: 18228
rv_id: 1262654
rule_id: ReUK9k
version_id: K3TKk5E
url: https://semgrep.dev/playground/r/K3TKk5E/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override
origin: community
- id: csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override
mode: taint
pattern-sources:
- patterns:
- focus-metavariable: $ARG
- pattern-inside: |
public $T $M(...,string $ARG,...){...}
pattern-sinks:
- patterns:
- pattern: |
XmlReader $READER = XmlReader.Create(...,$RS,...);
- pattern-inside: "XmlReaderSettings $RS = new XmlReaderSettings();\n...\n$RS.DtdProcessing
= DtdProcessing.Parse;\n... \n"
message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling
a string argument from a public method. Enabling Document Type Definition (DTD)
parsing may cause XML External Entity (XXE) injection if supplied with user-controllable
data.
languages:
- csharp
severity: WARNING
metadata:
category: security
references:
- https://www.jardinesoftware.net/2016/05/26/xxe-and-net/
- https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks
technology:
- .net
- xml
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
impact: MEDIUM
likelihood: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override
shortlink: https://sg.run/wXjA
semgrep.dev:
rule:
r_id: 18229
rv_id: 1262655
rule_id: AbU3pX
version_id: qkTR7WD
url: https://semgrep.dev/playground/r/qkTR7WD/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override
origin: community
- id: csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults
mode: taint
pattern-sources:
- patterns:
- focus-metavariable: $ARG
- pattern-inside: |
public $T $M(...,string $ARG,...){...}
pattern-sinks:
- patterns:
- pattern: |
$READER.$METHOD(...)
- pattern-not-inside: |
$READER.DtdProcessing = DtdProcessing.Prohibit;
...
- pattern-inside: |
XmlTextReader $READER = new XmlTextReader(...);
...
message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling
a string argument from a public method. Enabling Document Type Definition (DTD)
parsing may cause XML External Entity (XXE) injection if supplied with user-controllable
data.
languages:
- csharp
severity: WARNING
metadata:
category: security
references:
- https://www.jardinesoftware.net/2016/05/26/xxe-and-net/
- https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks
technology:
- .net
- xml
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
impact: MEDIUM
likelihood: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults
shortlink: https://sg.run/xXjL
semgrep.dev:
rule:
r_id: 18230
rv_id: 1262656
rule_id: BYUevk
version_id: l4TJRWG
url: https://semgrep.dev/playground/r/l4TJRWG/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults
origin: community
- id: go.aws-lambda.security.database-sqli.database-sqli
languages:
- go
message: Detected SQL statement that is tainted by `$EVENT` object. This could lead
to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use prepared statements with the 'Prepare' and 'PrepareContext'
calls.
mode: taint
metadata:
references:
- https://pkg.go.dev/database/sql#DB.Query
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- database
- sql
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/go.aws-lambda.security.database-sqli.database-sqli
shortlink: https://sg.run/e5e8
semgrep.dev:
rule:
r_id: 18232
rv_id: 1262909
rule_id: WAUdJ7
version_id: BjTkZkQ
url: https://semgrep.dev/playground/r/BjTkZkQ/go.aws-lambda.security.database-sqli.database-sqli
origin: community
pattern-sinks:
- patterns:
- focus-metavariable: $QUERY
- pattern-either:
- pattern: $DB.Exec($QUERY,...)
- pattern: $DB.ExecContent($QUERY,...)
- pattern: $DB.Query($QUERY,...)
- pattern: $DB.QueryContext($QUERY,...)
- pattern: $DB.QueryRow($QUERY,...)
- pattern: $DB.QueryRowContext($QUERY,...)
- pattern-inside: |
import "database/sql"
...
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...}
...
lambda.Start($HANDLER, ...)
- patterns:
- pattern-inside: |
func $HANDLER($EVENT $TYPE) {...}
...
lambda.Start($HANDLER, ...)
- pattern-not-inside: |
func $HANDLER($EVENT context.Context) {...}
...
lambda.Start($HANDLER, ...)
- focus-metavariable: $EVENT
severity: WARNING
- id: go.aws-lambda.security.tainted-sql-string.tainted-sql-string
languages:
- go
severity: ERROR
message: Detected user input used to manually construct a SQL string. This is usually
bad practice because manual construction could accidentally result in a SQL injection.
An attacker could use a SQL injection to steal or modify contents of the database.
Instead, use a parameterized query which is available by default in most database
engines. Alternatively, consider using an object-relational mapper (ORM) such
as Sequelize which will protect your queries.
metadata:
references:
- https://owasp.org/www-community/attacks/SQL_Injection
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/go.aws-lambda.security.tainted-sql-string.tainted-sql-string
shortlink: https://sg.run/vX3Y
semgrep.dev:
rule:
r_id: 18233
rv_id: 1262910
rule_id: 0oUwqg
version_id: DkTRbRL
url: https://semgrep.dev/playground/r/DkTRbRL/go.aws-lambda.security.tainted-sql-string.tainted-sql-string
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...}
...
lambda.Start($HANDLER, ...)
- patterns:
- pattern-inside: |
func $HANDLER($EVENT $TYPE) {...}
...
lambda.Start($HANDLER, ...)
- pattern-not-inside: |
func $HANDLER($EVENT context.Context) {...}
...
lambda.Start($HANDLER, ...)
- focus-metavariable: $EVENT
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: |
"$SQLSTR" + ...
- metavariable-regex:
metavariable: $SQLSTR
regex: (?i)(\s*select|\s*delete|\s*insert|\s*create|\s*update|\s*alter|\s*drop).*
- patterns:
- pattern-either:
- pattern: fmt.Fprintf($F, "$SQLSTR", ...)
- pattern: fmt.Sprintf("$SQLSTR", ...)
- pattern: fmt.Printf("$SQLSTR", ...)
- metavariable-regex:
metavariable: $SQLSTR
regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).*
- pattern-not-inside: |
log.$PRINT(...)
pattern-sanitizers:
- pattern: strconv.Atoi(...)
- id: go.lang.security.filepath-clean-misuse.filepath-clean-misuse
message: '`Clean` is not intended to sanitize against path traversal attacks. This
function is for finding the shortest path name equivalent to the given input.
Using `Clean` to sanitize file reads may expose this application to path traversal
attacks, where an attacker could access arbitrary files on the server. To fix
this easily, write this: `filepath.FromSlash(path.Clean("/"+strings.Trim(req.URL.Path,
"/")))` However, a better solution is using the `SecureJoin` function in the package
`filepath-securejoin`. See https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme.'
severity: ERROR
languages:
- go
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
($REQUEST : *http.Request).$ANYTHING
- pattern: |
($REQUEST : http.Request).$ANYTHING
- metavariable-regex:
metavariable: $ANYTHING
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
pattern-sinks:
- patterns:
- pattern-either:
- pattern: filepath.Clean($...INNER)
- pattern: path.Clean($...INNER)
pattern-sanitizers:
- pattern-either:
- pattern: |
"/" + ...
fix: filepath.FromSlash(filepath.Clean("/"+strings.Trim($...INNER, "/")))
options:
interfile: true
metadata:
references:
- https://pkg.go.dev/path#Clean
- http://technosophos.com/2016/03/31/go-quickly-cleaning-filepaths.html
- https://labs.detectify.com/2021/12/15/zero-day-path-traversal-grafana/
- https://dzx.cz/2021/04/02/go_path_traversal/
- https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
category: security
technology:
- go
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/go.lang.security.filepath-clean-misuse.filepath-clean-misuse
shortlink: https://sg.run/ZKzw
semgrep.dev:
rule:
r_id: 18235
rv_id: 1262967
rule_id: qNUQJe
version_id: jQTn5Bj
url: https://semgrep.dev/playground/r/jQTn5Bj/go.lang.security.filepath-clean-misuse.filepath-clean-misuse
origin: community
- id: java.aws-lambda.security.tainted-sql-string.tainted-sql-string
languages:
- java
severity: ERROR
message: Detected user input used to manually construct a SQL string. This is usually
bad practice because manual construction could accidentally result in a SQL injection.
An attacker could use a SQL injection to steal or modify contents of the database.
Instead, use a parameterized query which is available by default in most database
engines. Alternatively, consider using an object-relational mapper (ORM) such
as Sequelize which will protect your queries.
options:
interfile: true
metadata:
references:
- https://owasp.org/www-community/attacks/SQL_Injection
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sql-string.tainted-sql-string
shortlink: https://sg.run/EBYN
semgrep.dev:
rule:
r_id: 18237
rv_id: 1262977
rule_id: YGUl4z
version_id: O9TpxQN
url: https://semgrep.dev/playground/r/O9TpxQN/java.aws-lambda.security.tainted-sql-string.tainted-sql-string
origin: community
mode: taint
pattern-sources:
- patterns:
- focus-metavariable: $EVENT
- pattern-either:
- pattern: |
$HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) {
...
}
- pattern: |
$HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) {
...
}
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
"$SQLSTR" + ...
- pattern: |
"$SQLSTR".concat(...)
- patterns:
- pattern-inside: |
StringBuilder $SB = new StringBuilder("$SQLSTR");
...
- pattern: $SB.append(...)
- patterns:
- pattern-inside: |
$VAR = "$SQLSTR";
...
- pattern: $VAR += ...
- pattern: String.format("$SQLSTR", ...)
- metavariable-regex:
metavariable: $SQLSTR
regex: (?i)(select|delete|insert|create|update|alter|drop)\b
- pattern-not-inside: |
System.out.$PRINTLN(...)
- id: java.aws-lambda.security.tainted-sqli.tainted-sqli
message: Detected SQL statement that is tainted by `$EVENT` object. This could lead
to SQL injection if variables in the SQL statement are not properly sanitized.
Use parameterized SQL queries or properly sanitize user input instead.
languages:
- java
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- focus-metavariable: $EVENT
- pattern-either:
- pattern: |
$HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) {
...
}
- pattern: |
$HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) {
...
}
pattern-sinks:
- patterns:
- pattern-either:
- pattern: "(java.sql.CallableStatement $STMT) = ...; \n"
- pattern: |
(java.sql.Statement $STMT) = ...;
- pattern: |
(java.sql.PreparedStatement $STMT) = ...;
- pattern: |
$VAR = $CONN.prepareStatement(...)
- pattern: |
$PATH.queryForObject(...);
- pattern: |
(java.util.Map<String, Object> $STMT) = $PATH.queryForMap(...);
- pattern: |
(org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...;
- patterns:
- pattern-inside: |
(String $SQL) = "$SQLSTR" + ...;
...
- pattern: $PATH.$SQLCMD(..., $SQL, ...);
- metavariable-regex:
metavariable: $SQLSTR
regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*)
- metavariable-regex:
metavariable: $SQLCMD
regex: (execute|query|executeUpdate|batchUpdate)
options:
interfile: true
metadata:
category: security
technology:
- sql
- java
- aws-lambda
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sqli.tainted-sqli
shortlink: https://sg.run/7942
semgrep.dev:
rule:
r_id: 18238
rv_id: 1262978
rule_id: 6JUDWk
version_id: e1Tyj4g
url: https://semgrep.dev/playground/r/e1Tyj4g/java.aws-lambda.security.tainted-sqli.tainted-sqli
origin: community
- id: java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request
message: Detected input from a HTTPServletRequest going into a SQL sink or statement.
This could lead to SQL injection if variables in the SQL statement are not properly
sanitized. Use parameterized SQL queries or properly sanitize user input instead.
severity: WARNING
metadata:
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
category: security
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
cwe2021-top25: true
cwe2022-top25: true
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
- https://owasp.org/www-community/attacks/SQL_Injection
subcategory:
- vuln
technology:
- sql
- java
- servlets
- spring
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request
shortlink: https://sg.run/Lg56
semgrep.dev:
rule:
r_id: 18239
rv_id: 1409390
rule_id: oqUBJG
version_id: 7ZTKJNj
url: https://semgrep.dev/playground/r/7ZTKJNj/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request
origin: community
languages:
- java
mode: taint
options:
taint_assume_safe_numbers: true
taint_assume_safe_booleans: true
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
(HttpServletRequest $REQ).$REQFUNC(...)
- pattern: "(ServletRequest $REQ).$REQFUNC(...) \n"
- metavariable-regex:
metavariable: $REQFUNC
regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString)
pattern-sinks:
- patterns:
- pattern-either:
- pattern: "(java.sql.CallableStatement $STMT) = ...; \n"
- pattern: |
(java.sql.Statement $STMT) = ...;
...
$OUTPUT = $STMT.$FUNC(...);
- pattern: |
(java.sql.PreparedStatement $STMT) = ...;
- pattern: |
$VAR = $CONN.prepareStatement(...)
- pattern: |
$PATH.queryForObject(...);
- pattern: |
(java.util.Map<String, Object> $STMT) = $PATH.queryForMap(...);
- pattern: |
(org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...;
- pattern: |
(org.springframework.jdbc.core.JdbcTemplate $TEMPL).batchUpdate(...)
- patterns:
- pattern-inside: |
(String $SQL) = "$SQLSTR" + ...;
...
- pattern: $PATH.$SQLCMD(..., $SQL, ...);
- metavariable-regex:
metavariable: $SQLSTR
regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*)
- metavariable-regex:
metavariable: $SQLCMD
regex: (execute|query|executeUpdate|batchUpdate)
- id: java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request
message: Detected input from a HTTPServletRequest going into a 'ProcessBuilder'
or 'exec' command. This could lead to command injection if variables passed into
the exec commands are not properly sanitized. Instead, avoid using these OS commands
with user-supplied input, or, if you must use these commands, use a whitelist
of specific values.
languages:
- java
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
(HttpServletRequest $REQ)
- patterns:
- pattern-inside: |
(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);
...
for (javax.servlet.http.Cookie $COOKIE: $COOKIES) {
...
}
- pattern: |
$COOKIE.getValue(...)
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
(ProcessBuilder $PB) = ...;
- patterns:
- pattern: |
(Process $P) = ...;
- pattern-not: |
(Process $P) = (java.lang.Runtime $R).exec(...);
- patterns:
- pattern: (java.lang.Runtime $R).exec($CMD, ...);
- focus-metavariable: $CMD
- patterns:
- pattern-either:
- pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder
$PB) = ...;\n...\n$PB.command($ARGLIST);\n"
- pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder
$PB) = ...;\n"
- pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(Process
$P) = ...;\n"
- pattern: |
$ARGLIST.add(...);
metadata:
category: security
technology:
- java
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request
shortlink: https://sg.run/8zPN
semgrep.dev:
rule:
r_id: 18240
rv_id: 1263042
rule_id: zdUWrg
version_id: LjTkg9J
url: https://semgrep.dev/playground/r/LjTkg9J/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request
origin: community
- id: java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request
message: Detected input from a HTTPServletRequest going into an LDAP query. This
could lead to LDAP injection if the input is not properly sanitized, which could
result in attackers modifying objects in the LDAP tree structure. Ensure data
passed to an LDAP query is not controllable or properly sanitize the data.
metadata:
cwe:
- 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP
Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://sensei.securecodewarrior.com/recipes/scw%3Ajava%3ALDAP-injection
category: security
technology:
- java
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- LDAP Injection
source: https://semgrep.dev/r/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request
shortlink: https://sg.run/gRg0
semgrep.dev:
rule:
r_id: 18241
rv_id: 1409392
rule_id: pKUXAv
version_id: 8KT3Pe6
url: https://semgrep.dev/playground/r/8KT3Pe6/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request
origin: community
severity: WARNING
languages:
- java
mode: taint
pattern-sources:
- patterns:
- pattern: (HttpServletRequest $REQ)
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
(javax.naming.directory.InitialDirContext $IDC).search(...)
- pattern: |
(javax.naming.directory.DirContext $CTX).search(...)
- pattern-not: |
(javax.naming.directory.InitialDirContext $IDC).search($Y, "...", ...)
- pattern-not: |
(javax.naming.directory.DirContext $CTX).search($Y, "...", ...)
- id: java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request
message: Detected input from a HTTPServletRequest going into a session command,
like `setAttribute`. User input into such a command could lead to an attacker
inputting malicious code into your session parameters, blurring the line between
what's trusted and untrusted, and therefore leading to a trust boundary violation.
This could lead to programmers trusting unvalidated data. Instead, thoroughly
sanitize user input before passing it into such function calls.
languages:
- java
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern: |
(HttpServletRequest $REQ).$FUNC(...)
- pattern-not: |
(HttpServletRequest $REQ).getSession()
- patterns:
- pattern-inside: |
(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);
...
for (javax.servlet.http.Cookie $COOKIE: $COOKIES) {
...
}
- pattern: |
$COOKIE.getValue(...)
- patterns:
- pattern-inside: |
$TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(... );
...
- pattern: |
$PARAM = $VALS[$INDEX];
- patterns:
- pattern-inside: |
$HEADERS = (HttpServletRequest $REQ).getHeaders(...);
...
$PARAM = $HEADERS.$FUNC(...);
...
- pattern: |
java.net.URLDecoder.decode($PARAM, ...)
pattern-sinks:
- patterns:
- pattern: (HttpServletRequest $REQ).getSession().$FUNC($NAME, $VALUE);
- metavariable-regex:
metavariable: $FUNC
regex: ^(putValue|setAttribute)$
- focus-metavariable: $VALUE
options:
interfile: true
metadata:
category: security
technology:
- java
cwe:
- 'CWE-501: Trust Boundary Violation'
owasp:
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request
shortlink: https://sg.run/QbDZ
semgrep.dev:
rule:
r_id: 18242
rv_id: 1409393
rule_id: 2ZU7Eo
version_id: gETrv9j
url: https://semgrep.dev/playground/r/gETrv9j/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request
origin: community
- id: java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request
message: Detected input from a HTTPServletRequest going into a XPath evaluate or
compile command. This could lead to xpath injection if variables passed into the
evaluate or compile commands are not properly sanitized. Xpath injection could
lead to unauthorized access to sensitive information in XML documents. Instead,
thoroughly sanitize user input or use parameterized xpath queries if you can.
languages:
- java
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern: |
(HttpServletRequest $REQ).$FUNC(...)
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
(javax.xml.xpath.XPath $XP).evaluate(...)
- pattern: |
(javax.xml.xpath.XPath $XP).compile(...).evaluate(...)
metadata:
category: security
technology:
- java
cwe:
- 'CWE-643: Improper Neutralization of Data within XPath Expressions (''XPath
Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XPath Injection
source: https://semgrep.dev/r/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request
shortlink: https://sg.run/3BvK
semgrep.dev:
rule:
r_id: 18243
rv_id: 1409394
rule_id: X5U5nj
version_id: QkTERKP
url: https://semgrep.dev/playground/r/QkTERKP/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request
origin: community
- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false
severity: ERROR
metadata:
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.2 Insecue XML Deserialization
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
version: '4'
references:
- https://semgrep.dev/blog/2022/xml-security-in-java
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
- https://blog.sonarsource.com/secure-xml-processor
- https://xerces.apache.org/xerces2-j/features.html
category: security
technology:
- java
- xml
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false
shortlink: https://sg.run/4Dv5
semgrep.dev:
rule:
r_id: 18244
rv_id: 1263057
rule_id: j2UrJ8
version_id: 0bTKzgX
url: https://semgrep.dev/playground/r/0bTKzgX/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false
origin: community
message: DOCTYPE declarations are enabled for $DBFACTORY. Without prohibiting external
entity declarations, this is vulnerable to XML external entity attacks. Disable
this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl"
to true. Alternatively, allow DOCTYPE declarations and only prohibit external
entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities"
and "http://xml.org/sax/features/external-parameter-entities" to false.
patterns:
- pattern: $DBFACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl",
false);
- pattern-not-inside: |
$RETURNTYPE $METHOD(...){
...
$DBF.setFeature("http://xml.org/sax/features/external-general-entities", false);
...
$DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
}
- pattern-not-inside: |
$RETURNTYPE $METHOD(...){
...
$DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
$DBF.setFeature("http://xml.org/sax/features/external-general-entities", false);
...
}
- pattern-not-inside: |
$RETURNTYPE $METHOD(...){
...
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
...
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, "");
...
}
- pattern-not-inside: |
$RETURNTYPE $METHOD(...){
...
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, "");
...
$DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
...
}
languages:
- java
- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing
severity: ERROR
metadata:
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.2 Insecue XML Deserialization
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
version: '4'
references:
- https://semgrep.dev/blog/2022/xml-security-in-java
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
- https://blog.sonarsource.com/secure-xml-processor
- https://xerces.apache.org/xerces2-j/features.html
category: security
technology:
- java
- xml
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing
shortlink: https://sg.run/PYBz
semgrep.dev:
rule:
r_id: 18245
rv_id: 1263058
rule_id: 10UPQB
version_id: K3TKk80
url: https://semgrep.dev/playground/r/K3TKk80/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing
origin: community
message: DOCTYPE declarations are enabled for this DocumentBuilderFactory. This
is vulnerable to XML external entity attacks. Disable this by setting the feature
"http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively,
allow DOCTYPE declarations and only prohibit external entities declarations. This
can be done by setting the features "http://xml.org/sax/features/external-general-entities"
and "http://xml.org/sax/features/external-parameter-entities" to false.
mode: taint
pattern-sources:
- by-side-effect: true
patterns:
- pattern-either:
- pattern: |
$FACTORY = DocumentBuilderFactory.newInstance();
- patterns:
- pattern: $FACTORY
- pattern-inside: |
class $C {
...
$V $FACTORY = DocumentBuilderFactory.newInstance();
...
}
- pattern-not-inside: |
class $C {
...
$V $FACTORY = DocumentBuilderFactory.newInstance();
static {
...
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
...
}
...
}
- pattern-not-inside: |
class $C {
...
$V $FACTORY = DocumentBuilderFactory.newInstance();
static {
...
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
...
}
...
}
- pattern-not-inside: |
class $C {
...
$V $FACTORY = DocumentBuilderFactory.newInstance();
static {
...
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
}
...
}
pattern-sinks:
- patterns:
- pattern: $FACTORY.newDocumentBuilder();
pattern-sanitizers:
- by-side-effect: true
pattern-either:
- patterns:
- pattern-either:
- pattern: |
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
- pattern: |
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
- pattern: |
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
- focus-metavariable: $FACTORY
- patterns:
- pattern-either:
- pattern-inside: |
class $C {
...
$T $M(...) {
...
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl",
true);
...
}
...
}
- pattern-inside: |
class $C {
...
$T $M(...) {
...
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
}
...
}
- pattern-inside: |
class $C {
...
$T $M(...) {
...
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false);
...
}
...
}
- pattern: $M($X)
- focus-metavariable: $X
fix: |
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
$FACTORY.newDocumentBuilder();
languages:
- java
- id: java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true
severity: ERROR
metadata:
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.2 Insecue XML Deserialization
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
version: '4'
references:
- https://semgrep.dev/blog/2022/xml-security-in-java
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
- https://blog.sonarsource.com/secure-xml-processor
category: security
technology:
- java
- xml
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true
shortlink: https://sg.run/JgPy
semgrep.dev:
rule:
r_id: 18246
rv_id: 1263059
rule_id: 9AUJ6r
version_id: qkTR7Lk
url: https://semgrep.dev/playground/r/qkTR7Lk/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true
origin: community
message: External entities are allowed for $DBFACTORY. This is vulnerable to XML
external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-general-entities"
to false.
pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities",
true);
fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities",
false);
languages:
- java
- id: java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true
severity: ERROR
metadata:
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.2 Insecue XML Deserialization
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
version: '4'
references:
- https://semgrep.dev/blog/2022/xml-security-in-java
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
- https://blog.sonarsource.com/secure-xml-processor
category: security
technology:
- java
- xml
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true
shortlink: https://sg.run/5Lv0
semgrep.dev:
rule:
r_id: 18247
rv_id: 1263060
rule_id: yyUNeo
version_id: l4TJRoL
url: https://semgrep.dev/playground/r/l4TJRoL/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true
origin: community
message: External entities are allowed for $DBFACTORY. This is vulnerable to XML
external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-parameter-entities"
to false.
pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities",
true);
fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities",
false);
languages:
- java
- id: javascript.aws-lambda.security.detect-child-process.detect-child-process
message: Allowing spawning arbitrary programs or running shell processes with arbitrary
arguments may end up in a command injection vulnerability. Try to avoid non-literal
values for the command string. If it is not possible, then do not let running
arbitrary commands, use a white list for inputs.
metadata:
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- javascript
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
references:
- https://owasp.org/Top10/A03_2021-Injection
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/javascript.aws-lambda.security.detect-child-process.detect-child-process
shortlink: https://sg.run/Ggoq
semgrep.dev:
rule:
r_id: 18248
rv_id: 1263105
rule_id: r6UDNQ
version_id: YDTZe4o
url: https://semgrep.dev/playground/r/YDTZe4o/javascript.aws-lambda.security.detect-child-process.detect-child-process
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern: $EVENT
- pattern-either:
- pattern-inside: |
exports.handler = function ($EVENT, ...) {
...
}
- pattern-inside: |
function $FUNC ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern-inside: |
$FUNC = function ($EVENT, ...) {...}
...
exports.handler = $FUNC
pattern-sinks:
- patterns:
- focus-metavariable: $CMD
- pattern-either:
- pattern: exec($CMD,...)
- pattern: execSync($CMD,...)
- pattern: spawn($CMD,...)
- pattern: spawnSync($CMD,...)
- pattern: $CP.exec($CMD,...)
- pattern: $CP.execSync($CMD,...)
- pattern: $CP.spawn($CMD,...)
- pattern: $CP.spawnSync($CMD,...)
- pattern-either:
- pattern-inside: |
require('child_process')
...
- pattern-inside: |
import 'child_process'
...
- id: javascript.aws-lambda.security.knex-sqli.knex-sqli
message: 'Detected SQL statement that is tainted by `$EVENT` object. This could
lead to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `knex.raw(''SELECT $1 from
table'', [userinput])`'
metadata:
references:
- https://knexjs.org/#Builder-fromRaw
- https://knexjs.org/#Builder-whereRaw
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- knex
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/javascript.aws-lambda.security.knex-sqli.knex-sqli
shortlink: https://sg.run/RgWq
semgrep.dev:
rule:
r_id: 18249
rv_id: 1263106
rule_id: bwUBlj
version_id: JdTzxKg
url: https://semgrep.dev/playground/r/JdTzxKg/javascript.aws-lambda.security.knex-sqli.knex-sqli
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
exports.handler = function ($EVENT, ...) {
...
}
- pattern-inside: |
function $FUNC ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern-inside: |
$FUNC = function ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern: $EVENT
pattern-sinks:
- patterns:
- focus-metavariable: $QUERY
- pattern-either:
- pattern: $KNEX.fromRaw($QUERY, ...)
- pattern: $KNEX.whereRaw($QUERY, ...)
- pattern: $KNEX.raw($QUERY, ...)
- pattern-either:
- pattern-inside: |
require('knex')
...
- pattern-inside: |
import 'knex'
...
- id: javascript.aws-lambda.security.mysql-sqli.mysql-sqli
message: 'Detected SQL statement that is tainted by `$EVENT` object. This could
lead to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `connection.query(''SELECT
$1 from table'', [userinput])`'
metadata:
references:
- https://www.npmjs.com/package/mysql2
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- mysql
- mysql2
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/javascript.aws-lambda.security.mysql-sqli.mysql-sqli
shortlink: https://sg.run/A502
semgrep.dev:
rule:
r_id: 18250
rv_id: 1263107
rule_id: NbUBJ2
version_id: 5PTo1En
url: https://semgrep.dev/playground/r/5PTo1En/javascript.aws-lambda.security.mysql-sqli.mysql-sqli
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
exports.handler = function ($EVENT, ...) {
...
}
- pattern-inside: |
function $FUNC ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern-inside: |
$FUNC = function ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern: $EVENT
pattern-sinks:
- patterns:
- focus-metavariable: $QUERY
- pattern-either:
- pattern: $POOL.query($QUERY, ...)
- pattern: $POOL.execute($QUERY, ...)
- pattern-either:
- pattern-inside: |
require('mysql')
...
- pattern-inside: |
require('mysql2')
...
- pattern-inside: |
require('mysql2/promise')
...
- pattern-inside: |
import 'mysql'
...
- pattern-inside: |
import 'mysql2'
...
- pattern-inside: |
import 'mysql2/promise'
...
- id: javascript.aws-lambda.security.pg-sqli.pg-sqli
message: 'Detected SQL statement that is tainted by `$EVENT` object. This could
lead to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `connection.query(''SELECT
$1 from table'', [userinput])`'
metadata:
references:
- https://node-postgres.com/features/queries
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- postgres
- pg
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/javascript.aws-lambda.security.pg-sqli.pg-sqli
shortlink: https://sg.run/BGKA
semgrep.dev:
rule:
r_id: 18251
rv_id: 1263108
rule_id: kxU25P
version_id: GxTkeJL
url: https://semgrep.dev/playground/r/GxTkeJL/javascript.aws-lambda.security.pg-sqli.pg-sqli
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
exports.handler = function ($EVENT, ...) {
...
}
- pattern-inside: |
function $FUNC ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern-inside: |
$FUNC = function ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern: $EVENT
pattern-sinks:
- patterns:
- focus-metavariable: $QUERY
- pattern-either:
- pattern: $DB.query($QUERY, ...)
- pattern-either:
- pattern-inside: |
require('pg')
...
- pattern-inside: |
import 'pg'
...
- id: javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli
message: 'Detected SQL statement that is tainted by `$EVENT` object. This could
lead to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `sequelize.query(''SELECT
* FROM projects WHERE status = ?'', { replacements: [''active''], type: QueryTypes.SELECT
});`'
metadata:
references:
- https://sequelize.org/master/manual/raw-queries.html
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- sequelize
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli
shortlink: https://sg.run/DAlP
semgrep.dev:
rule:
r_id: 18252
rv_id: 1263109
rule_id: wdUA5o
version_id: RGT0LrD
url: https://semgrep.dev/playground/r/RGT0LrD/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
exports.handler = function ($EVENT, ...) {
...
}
- pattern-inside: |
function $FUNC ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern-inside: |
$FUNC = function ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern: $EVENT
pattern-sinks:
- patterns:
- focus-metavariable: $QUERY
- pattern-either:
- pattern: $DB.query($QUERY, ...)
- pattern-either:
- pattern-inside: |
require('sequelize')
...
- pattern-inside: |
import 'sequelize'
...
- id: javascript.aws-lambda.security.tainted-html-response.tainted-html-response
message: Detected user input flowing into an HTML response. You may be accidentally
bypassing secure methods of rendering HTML by manually constructing HTML and this
could create a cross-site scripting vulnerability, which could let attackers steal
sensitive user data.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
references:
- https://owasp.org/Top10/A03_2021-Injection
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-response.tainted-html-response
shortlink: https://sg.run/0Gvj
semgrep.dev:
rule:
r_id: 18254
rv_id: 1263111
rule_id: OrUJBY
version_id: BjTkZ8D
url: https://semgrep.dev/playground/r/BjTkZ8D/javascript.aws-lambda.security.tainted-html-response.tainted-html-response
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
exports.handler = function ($EVENT, ...) {
...
}
- pattern-inside: |
function $FUNC ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern-inside: |
$FUNC = function ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern: $EVENT
pattern-sinks:
- patterns:
- focus-metavariable: $BODY
- pattern-inside: |
{..., headers: {..., 'Content-Type': 'text/html', ...}, body: $BODY, ... }
- id: javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection
message: The `vm` module enables compiling and running code within V8 Virtual Machine
contexts. The `vm` module is not a security mechanism. Do not use it to run untrusted
code. If code passed to `vm` functions is controlled by user input it could result
in command injection. Do not let user input in `vm` functions.
metadata:
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
category: security
technology:
- javascript
- aws-lambda
cwe2022-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
references:
- https://owasp.org/Top10/A03_2021-Injection
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection
shortlink: https://sg.run/q9w7
semgrep.dev:
rule:
r_id: 18256
rv_id: 1263114
rule_id: v8UOdZ
version_id: 0bTKz9J
url: https://semgrep.dev/playground/r/0bTKz9J/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern: $EVENT
- pattern-either:
- pattern-inside: |
exports.handler = function ($EVENT, ...) {
...
}
- pattern-inside: |
function $FUNC ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern-inside: |
$FUNC = function ($EVENT, ...) {...}
...
exports.handler = $FUNC
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
require('vm');
...
- pattern-inside: |
import 'vm'
...
- pattern-either:
- pattern: $VM.runInContext($X,...)
- pattern: $VM.runInNewContext($X,...)
- pattern: $VM.runInThisContext($X,...)
- pattern: $VM.compileFunction($X,...)
- pattern: new $VM.Script($X,...)
- pattern: new $VM.SourceTextModule($X,...)
- pattern: runInContext($X,...)
- pattern: runInNewContext($X,...)
- pattern: runInThisContext($X,...)
- pattern: compileFunction($X,...)
- pattern: new Script($X,...)
- pattern: new SourceTextModule($X,...)
- id: javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli
message: 'Detected SQL statement that is tainted by `$REQ` object. This could lead
to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, it is recommended to use parameterized queries
or prepared statements. An example of parameterized queries like so: `knex.raw(''SELECT
$1 from table'', [userinput])` can help prevent SQLi.'
metadata:
confidence: MEDIUM
references:
- https://knexjs.org/#Builder-fromRaw
- https://knexjs.org/#Builder-whereRaw
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- express
- nodejs
- knex
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli
shortlink: https://sg.run/l9eE
semgrep.dev:
rule:
r_id: 18257
rv_id: 1263205
rule_id: d8UKLD
version_id: l4TJRey
url: https://semgrep.dev/playground/r/l4TJRey/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
- pattern: files.$ANYTHING.data.toString('utf8')
- pattern: files.$ANYTHING['data'].toString('utf8')
pattern-sinks:
- patterns:
- focus-metavariable: $QUERY
- pattern-either:
- pattern-inside: $KNEX.fromRaw($QUERY, ...)
- pattern-inside: $KNEX.whereRaw($QUERY, ...)
- pattern-inside: $KNEX.raw($QUERY, ...)
- pattern-either:
- pattern-inside: |
require('knex')
...
- pattern-inside: |
import 'knex'
...
pattern-sanitizers:
- patterns:
- pattern: parseInt(...)
- id: php.lang.security.deserialization.extract-user-data
mode: taint
pattern-sources:
- pattern-either:
- pattern: $_GET[...]
- pattern: $_FILES[...]
- pattern: $_POST[...]
pattern-sinks:
- pattern: extract(...)
pattern-sanitizers:
- pattern: extract($VAR, EXTR_SKIP,...)
message: Do not call 'extract()' on user-controllable data. If you must, then you
must also provide the EXTR_SKIP flag to prevent overwriting existing variables.
languages:
- php
metadata:
category: security
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
technology:
- php
references:
- https://www.php.net/manual/en/function.extract.php#refsect1-function.extract-notes
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/php.lang.security.deserialization.extract-user-data
shortlink: https://sg.run/6bv1
semgrep.dev:
rule:
r_id: 18259
rv_id: 1263278
rule_id: nJUykq
version_id: w8TRovw
url: https://semgrep.dev/playground/r/w8TRovw/php.lang.security.deserialization.extract-user-data
origin: community
severity: ERROR
- id: python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec
mode: taint
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
pattern-sinks:
- patterns:
- focus-metavariable: $CMD
- pattern-either:
- pattern: asyncio.create_subprocess_exec($PROG, $CMD, ...)
- pattern: asyncio.create_subprocess_exec($PROG, [$CMD, ...], ...)
- pattern: asyncio.subprocess.create_subprocess_exec($PROG, $CMD, ...)
- pattern: asyncio.subprocess.create_subprocess_exec($PROG, [$CMD, ...], ...)
- pattern: asyncio.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/",
"-c", $CMD, ...)
- pattern: asyncio.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/",
"-c", $CMD, ...], ...)
- pattern: asyncio.subprocess.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/",
"-c", $CMD, ...)
- pattern: asyncio.subprocess.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/",
"-c", $CMD, ...], ...)
message: Detected 'create_subprocess_exec' function with argument tainted by `event`
object. If this data can be controlled by a malicious actor, it may be an instance
of command injection. Audit the use of this call to ensure it is not controllable
by an external resource. You may consider using 'shlex.escape()'.
metadata:
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
references:
- https://docs.python.org/3/library/asyncio-subprocess.html#asyncio.create_subprocess_exec
- https://docs.python.org/3/library/shlex.html
category: security
technology:
- python
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec
shortlink: https://sg.run/oyv0
semgrep.dev:
rule:
r_id: 18260
rv_id: 1263331
rule_id: EwUrX8
version_id: rxTAKgo
url: https://semgrep.dev/playground/r/rxTAKgo/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec
origin: community
languages:
- python
severity: ERROR
- id: python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec
mode: taint
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
pattern-sinks:
- patterns:
- focus-metavariable: $CMD
- pattern-either:
- pattern: $LOOP.subprocess_exec($PROTOCOL, $CMD, ...)
- pattern: $LOOP.subprocess_exec($PROTOCOL, [$CMD, ...], ...)
- pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/",
"-c", $CMD, ...)
- pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/",
"-c", $CMD, ...], ...)
message: Detected subprocess function '$LOOP.subprocess_exec' with argument tainted
by `event` object. If this data can be controlled by a malicious actor, it may
be an instance of command injection. Audit the use of this call to ensure it is
not controllable by an external resource. You may consider using 'shlex.escape()'.
metadata:
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
references:
- https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec
- https://docs.python.org/3/library/shlex.html
category: security
technology:
- python
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec
shortlink: https://sg.run/z14d
semgrep.dev:
rule:
r_id: 18261
rv_id: 1263332
rule_id: 7KUxXg
version_id: bZT53Ww
url: https://semgrep.dev/playground/r/bZT53Ww/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec
origin: community
languages:
- python
severity: ERROR
- id: python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell
mode: taint
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
pattern-sinks:
- patterns:
- focus-metavariable: $CMD
- pattern-either:
- pattern: $LOOP.subprocess_shell($PROTOCOL, $CMD)
- pattern: asyncio.subprocess.create_subprocess_shell($CMD, ...)
- pattern: asyncio.create_subprocess_shell($CMD, ...)
message: Detected asyncio subprocess function with argument tainted by `event` object.
If this data can be controlled by a malicious actor, it may be an instance of
command injection. Audit the use of this call to ensure it is not controllable
by an external resource. You may consider using 'shlex.escape()'.
metadata:
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
references:
- https://docs.python.org/3/library/asyncio-subprocess.html
- https://docs.python.org/3/library/shlex.html
category: security
technology:
- python
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell
shortlink: https://sg.run/p9vZ
semgrep.dev:
rule:
r_id: 18262
rv_id: 1263333
rule_id: L1UEl7
version_id: NdTzyWA
url: https://semgrep.dev/playground/r/NdTzyWA/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell
origin: community
languages:
- python
severity: ERROR
- id: python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process
mode: taint
message: Detected `os` function with argument tainted by `event` object. This is
dangerous if external data can reach this function call because it allows a malicious
actor to execute commands. Ensure no external data reaches here.
metadata:
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
category: security
technology:
- python
- aws-lambda
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process
shortlink: https://sg.run/2AjL
semgrep.dev:
rule:
r_id: 18263
rv_id: 1263334
rule_id: 8GUGBq
version_id: kbTzGv8
url: https://semgrep.dev/playground/r/kbTzGv8/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process
origin: community
languages:
- python
severity: ERROR
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
pattern-sinks:
- patterns:
- focus-metavariable: $CMD
- pattern-either:
- patterns:
- pattern: os.$METHOD($MODE, $CMD, ...)
- metavariable-regex:
metavariable: $METHOD
regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile)
- patterns:
- pattern-inside: os.$METHOD($MODE, $BASH, ["-c", $CMD,...],...)
- metavariable-regex:
metavariable: $METHOD
regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp)
- metavariable-regex:
metavariable: $BASH
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
- patterns:
- pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...)
- metavariable-regex:
metavariable: $METHOD
regex: (spawnl|spawnle|spawnlp|spawnlpe)
- metavariable-regex:
metavariable: $BASH
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
- id: python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use
mode: taint
message: Detected subprocess function with argument tainted by an `event` object. If
this data can be controlled by a malicious actor, it may be an instance of command
injection. The default option for `shell` is False, and this is secure by default.
Consider removing the `shell=True` or setting it to False explicitely. Using `shell=False`
means you have to split the command string into an array of strings for the command
and its arguments. You may consider using 'shlex.split()' for this purpose.
metadata:
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
references:
- https://docs.python.org/3/library/subprocess.html
- https://docs.python.org/3/library/shlex.html
category: security
technology:
- python
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use
shortlink: https://sg.run/XZ7B
semgrep.dev:
rule:
r_id: 18264
rv_id: 1263335
rule_id: gxUyn1
version_id: w8TRogj
url: https://semgrep.dev/playground/r/w8TRogj/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use
origin: community
languages:
- python
severity: ERROR
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
pattern-sinks:
- patterns:
- pattern: subprocess.$FUNC(..., shell=True, ...)
pattern-sanitizers:
- pattern: shlex.split(...)
- pattern: pipes.quote(...)
- pattern: shlex.quote(...)
- id: python.aws-lambda.security.dangerous-system-call.dangerous-system-call
mode: taint
message: Detected `os` function with argument tainted by `event` object. This is
dangerous if external data can reach this function call because it allows a malicious
actor to execute commands. Use the 'subprocess' module instead, which is easier
to use without accidentally exposing a command injection vulnerability.
metadata:
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.2.4 Dyanmic Code Execution Features
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements
version: '4'
category: security
technology:
- python
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-system-call.dangerous-system-call
shortlink: https://sg.run/jDvN
semgrep.dev:
rule:
r_id: 18265
rv_id: 1263336
rule_id: QrUkg6
version_id: xyTjzbG
url: https://semgrep.dev/playground/r/xyTjzbG/python.aws-lambda.security.dangerous-system-call.dangerous-system-call
origin: community
languages:
- python
severity: ERROR
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
pattern-sinks:
- patterns:
- focus-metavariable: $CMD
- pattern-either:
- pattern: os.system($CMD,...)
- pattern: os.popen($CMD,...)
- pattern: os.popen2($CMD,...)
- pattern: os.popen3($CMD,...)
- pattern: os.popen4($CMD,...)
- id: python.aws-lambda.security.mysql-sqli.mysql-sqli
languages:
- python
message: 'Detected SQL statement that is tainted by `event` object. This could lead
to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `cursor.execute(''SELECT
* FROM projects WHERE status = %s'', (''active''))`'
mode: taint
metadata:
references:
- https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-execute.html
- https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-executemany.html
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- mysql
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.aws-lambda.security.mysql-sqli.mysql-sqli
shortlink: https://sg.run/1RjG
semgrep.dev:
rule:
r_id: 18266
rv_id: 1263337
rule_id: 3qU3eE
version_id: O9TpxLJ
url: https://semgrep.dev/playground/r/O9TpxLJ/python.aws-lambda.security.mysql-sqli.mysql-sqli
origin: community
pattern-sinks:
- patterns:
- focus-metavariable: $QUERY
- pattern-either:
- pattern: $CURSOR.execute($QUERY,...)
- pattern: $CURSOR.executemany($QUERY,...)
- pattern-either:
- pattern-inside: |
import mysql
...
- pattern-inside: |
import mysql.cursors
...
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
severity: WARNING
- id: python.aws-lambda.security.psycopg-sqli.psycopg-sqli
languages:
- python
message: 'Detected SQL statement that is tainted by `event` object. This could lead
to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `cursor.execute(''SELECT
* FROM projects WHERE status = %s'', ''active'')`'
mode: taint
metadata:
references:
- https://www.psycopg.org/docs/cursor.html#cursor.execute
- https://www.psycopg.org/docs/cursor.html#cursor.executemany
- https://www.psycopg.org/docs/cursor.html#cursor.mogrify
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- psycopg
- psycopg2
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.aws-lambda.security.psycopg-sqli.psycopg-sqli
shortlink: https://sg.run/9L8r
semgrep.dev:
rule:
r_id: 18267
rv_id: 1263338
rule_id: 4bUQG1
version_id: e1TyjPZ
url: https://semgrep.dev/playground/r/e1TyjPZ/python.aws-lambda.security.psycopg-sqli.psycopg-sqli
origin: community
pattern-sinks:
- patterns:
- focus-metavariable: $QUERY
- pattern-either:
- pattern: $CURSOR.execute($QUERY,...)
- pattern: $CURSOR.executemany($QUERY,...)
- pattern: $CURSOR.mogrify($QUERY,...)
- pattern-inside: |
import psycopg2
...
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
severity: WARNING
- id: python.aws-lambda.security.pymssql-sqli.pymssql-sqli
languages:
- python
message: 'Detected SQL statement that is tainted by `event` object. This could lead
to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `cursor.execute(''SELECT
* FROM projects WHERE status = %s'', ''active'')`'
mode: taint
metadata:
references:
- https://pypi.org/project/pymssql/
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- pymssql
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.aws-lambda.security.pymssql-sqli.pymssql-sqli
shortlink: https://sg.run/yXvP
semgrep.dev:
rule:
r_id: 18268
rv_id: 1263339
rule_id: PeUxO0
version_id: vdT06bG
url: https://semgrep.dev/playground/r/vdT06bG/python.aws-lambda.security.pymssql-sqli.pymssql-sqli
origin: community
pattern-sinks:
- patterns:
- focus-metavariable: $QUERY
- pattern: $CURSOR.execute($QUERY,...)
- pattern-inside: |
import pymssql
...
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
severity: WARNING
- id: python.aws-lambda.security.pymysql-sqli.pymysql-sqli
languages:
- python
message: 'Detected SQL statement that is tainted by `event` object. This could lead
to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `cursor.execute(''SELECT
* FROM projects WHERE status = %s'', (''active''))`'
mode: taint
metadata:
references:
- https://pypi.org/project/PyMySQL/#id4
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- pymysql
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.aws-lambda.security.pymysql-sqli.pymysql-sqli
shortlink: https://sg.run/reve
semgrep.dev:
rule:
r_id: 18269
rv_id: 1263340
rule_id: JDUlel
version_id: d6TyxNA
url: https://semgrep.dev/playground/r/d6TyxNA/python.aws-lambda.security.pymysql-sqli.pymysql-sqli
origin: community
pattern-sinks:
- patterns:
- focus-metavariable: $QUERY
- pattern: $CURSOR.execute($QUERY,...)
- pattern-either:
- pattern-inside: |
import pymysql
...
- pattern-inside: |
import pymysql.cursors
...
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
severity: WARNING
- id: python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli
languages:
- python
message: 'Detected SQL statement that is tainted by `event` object. This could lead
to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `cursor.execute(''SELECT
* FROM projects WHERE status = ?'', ''active'')`'
mode: taint
metadata:
references:
- https://docs.sqlalchemy.org/en/14/core/connections.html#sqlalchemy.engine.Connection.execute
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- sqlalchemy
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli
shortlink: https://sg.run/b48W
semgrep.dev:
rule:
r_id: 18270
rv_id: 1263341
rule_id: 5rUy3N
version_id: ZRTKARp
url: https://semgrep.dev/playground/r/ZRTKARp/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli
origin: community
pattern-sinks:
- patterns:
- focus-metavariable: $QUERY
- pattern: $CURSOR.execute($QUERY,...)
- pattern-inside: |
import sqlalchemy
...
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
severity: WARNING
- id: python.aws-lambda.security.tainted-code-exec.tainted-code-exec
mode: taint
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
pattern-sinks:
- patterns:
- pattern-either:
- pattern: eval($CODE, ...)
- pattern: exec($CODE, ...)
message: Detected the use of `exec/eval`.This can be dangerous if used to evaluate
dynamic content. If this content can be input from outside the program, this may
be a code injection vulnerability. Ensure evaluated content is not definable by
external sources.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.2.4 Dyanmic Code Execution Features
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements
version: '4'
category: security
technology:
- python
references:
- https://owasp.org/Top10/A03_2021-Injection
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.aws-lambda.security.tainted-code-exec.tainted-code-exec
shortlink: https://sg.run/Ng7y
semgrep.dev:
rule:
r_id: 18271
rv_id: 1263342
rule_id: GdUDJP
version_id: nWT2LD2
url: https://semgrep.dev/playground/r/nWT2LD2/python.aws-lambda.security.tainted-code-exec.tainted-code-exec
origin: community
languages:
- python
severity: WARNING
- id: python.aws-lambda.security.tainted-html-response.tainted-html-response
mode: taint
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
pattern-sinks:
- patterns:
- pattern: $BODY
- pattern-inside: |
{..., "headers": {..., "Content-Type": "text/html", ...}, "body": $BODY, ... }
message: Detected user input flowing into an HTML response. You may be accidentally
bypassing secure methods of rendering HTML by manually constructing HTML and this
could create a cross-site scripting vulnerability, which could let attackers steal
sensitive user data.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- aws-lambda
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-response.tainted-html-response
shortlink: https://sg.run/k9vP
semgrep.dev:
rule:
r_id: 18272
rv_id: 1263343
rule_id: ReUKrk
version_id: ExTEx5o
url: https://semgrep.dev/playground/r/ExTEx5o/python.aws-lambda.security.tainted-html-response.tainted-html-response
origin: community
languages:
- python
severity: WARNING
- id: python.aws-lambda.security.tainted-sql-string.tainted-sql-string
languages:
- python
message: Detected user input used to manually construct a SQL string. This is usually
bad practice because manual construction could accidentally result in a SQL injection.
An attacker could use a SQL injection to steal or modify contents of the database.
Instead, use a parameterized query which is available by default in most database
engines. Alternatively, consider using an object-relational mapper (ORM) such
as Sequelize which will protect your queries.
metadata:
references:
- https://owasp.org/www-community/attacks/SQL_Injection
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.aws-lambda.security.tainted-sql-string.tainted-sql-string
shortlink: https://sg.run/wXvA
semgrep.dev:
rule:
r_id: 18273
rv_id: 1263346
rule_id: AbU3LX
version_id: 8KT5ron
url: https://semgrep.dev/playground/r/8KT5ron/python.aws-lambda.security.tainted-sql-string.tainted-sql-string
origin: community
mode: taint
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
"$SQLSTR" + ...
- pattern: |
"$SQLSTR" % ...
- pattern: |
"$SQLSTR".format(...)
- pattern: |
f"$SQLSTR{...}..."
- metavariable-regex:
metavariable: $SQLSTR
regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*=
- pattern-not-inside: |
print(...)
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
severity: ERROR
- id: ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli
languages:
- ruby
message: 'Detected SQL statement that is tainted by `event` object. This could lead
to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `Example.find_by_sql ["SELECT
title FROM posts WHERE author = ? AND created > ?", author_id, start_date]`'
mode: taint
metadata:
references:
- https://guides.rubyonrails.org/active_record_querying.html#finding-by-sql
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- active-record
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli
shortlink: https://sg.run/vXvY
semgrep.dev:
rule:
r_id: 18277
rv_id: 1263581
rule_id: 0oUw9g
version_id: w8TRor7
url: https://semgrep.dev/playground/r/w8TRor7/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli
origin: community
pattern-sinks:
- patterns:
- pattern: $QUERY
- pattern-either:
- pattern: ActiveRecord::Base.connection.execute($QUERY,...)
- pattern: $MODEL.find_by_sql($QUERY,...)
- pattern: $MODEL.select_all($QUERY,...)
- pattern-inside: |
require 'active_record'
...
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context)
...
end
severity: WARNING
- id: ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli
languages:
- ruby
message: 'Detected SQL statement that is tainted by `event` object. This could lead
to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use sanitize statements like so: `escaped = client.escape(user_input)`'
mode: taint
metadata:
references:
- https://github.com/brianmario/mysql2
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- mysql2
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli
shortlink: https://sg.run/dJLE
semgrep.dev:
rule:
r_id: 18278
rv_id: 1263582
rule_id: KxUrQ3
version_id: xyTjzOe
url: https://semgrep.dev/playground/r/xyTjzOe/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli
origin: community
pattern-sinks:
- patterns:
- pattern: $QUERY
- pattern-either:
- pattern: $CLIENT.query($QUERY,...)
- pattern: $CLIENT.prepare($QUERY,...)
- pattern-inside: |
require 'mysql2'
...
pattern-sanitizers:
- pattern: $CLIENT.escape(...)
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context)
...
end
severity: WARNING
- id: ruby.aws-lambda.security.pg-sqli.pg-sqli
languages:
- ruby
message: 'Detected SQL statement that is tainted by `event` object. This could lead
to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `conn.exec_params(''SELECT
$1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])`'
mode: taint
metadata:
references:
- https://www.rubydoc.info/gems/pg/PG/Connection
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- postgres
- pg
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/ruby.aws-lambda.security.pg-sqli.pg-sqli
shortlink: https://sg.run/ZKww
semgrep.dev:
rule:
r_id: 18279
rv_id: 1263583
rule_id: qNUQee
version_id: O9Tpxz7
url: https://semgrep.dev/playground/r/O9Tpxz7/ruby.aws-lambda.security.pg-sqli.pg-sqli
origin: community
pattern-sinks:
- patterns:
- pattern: $QUERY
- pattern-either:
- pattern: $CONN.exec($QUERY,...)
- pattern: $CONN.exec_params($QUERY,...)
- pattern: $CONN.exec_prepared($QUERY,...)
- pattern: $CONN.async_exec($QUERY,...)
- pattern: $CONN.async_exec_params($QUERY,...)
- pattern: $CONN.async_exec_prepared($QUERY,...)
- pattern-inside: |
require 'pg'
...
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context)
...
end
severity: WARNING
- id: ruby.aws-lambda.security.sequel-sqli.sequel-sqli
languages:
- ruby
message: 'Detected SQL statement that is tainted by `event` object. This could lead
to SQL injection if the variable is user-controlled and not properly sanitized.
In order to prevent SQL injection, use parameterized queries or prepared statements
instead. You can use parameterized statements like so: `DB[''select * from items
where name = ?'', name]`'
mode: taint
metadata:
references:
- https://github.com/jeremyevans/sequel#label-Arbitrary+SQL+queries
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
- sequel
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/ruby.aws-lambda.security.sequel-sqli.sequel-sqli
shortlink: https://sg.run/n9vY
semgrep.dev:
rule:
r_id: 18280
rv_id: 1263584
rule_id: lBUy2N
version_id: e1Tyj5j
url: https://semgrep.dev/playground/r/e1Tyj5j/ruby.aws-lambda.security.sequel-sqli.sequel-sqli
origin: community
pattern-sinks:
- patterns:
- pattern: $QUERY
- pattern-either:
- pattern: DB[$QUERY,...]
- pattern: DB.run($QUERY,...)
- pattern-inside: |
require 'sequel'
...
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context)
...
end
severity: WARNING
- id: ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string
languages:
- ruby
severity: ERROR
message: Detected user input used to manually construct a SQL string. This is usually
bad practice because manual construction could accidentally result in a SQL injection.
An attacker could use a SQL injection to steal or modify contents of the database.
Instead, use a parameterized query which is available by default in most database
engines. Alternatively, consider using an object-relational mapper (ORM) such
as Sequelize which will protect your queries.
metadata:
references:
- https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet
category: security
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
technology:
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string
shortlink: https://sg.run/EB7N
semgrep.dev:
rule:
r_id: 18281
rv_id: 1263586
rule_id: PeUxOE
version_id: d6Tyx1Z
url: https://semgrep.dev/playground/r/d6Tyx1Z/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context)
...
end
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: |
"...#{...}..."
- pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].*
- patterns:
- pattern-either:
- pattern: Kernel::sprintf("$SQLSTR", ...)
- pattern: |
"$SQLSTR" + $EXPR
- pattern: |
"$SQLSTR" % $EXPR
- metavariable-regex:
metavariable: $SQLSTR
regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].*
- pattern-not-inside: |
puts(...)
- id: scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings
patterns:
- pattern: secure = false
- pattern-inside: |
session = {
...
}
message: Session cookie `Secure` flag is explicitly disabled. The `secure` flag
for cookies prevents the client from transmitting the cookie over insecure channels
such as HTTP. Set the `Secure` flag by setting `secure` to `true` in configuration
file.
languages:
- generic
severity: WARNING
paths:
include:
- '*.conf'
metadata:
category: security
references:
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#security
- https://www.playframework.com/documentation/2.8.x/SettingsSession#Session-Configuration
technology:
- play
- scala
cwe:
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
confidence: MEDIUM
subcategory:
- vuln
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings
shortlink: https://sg.run/8z8N
semgrep.dev:
rule:
r_id: 18284
rv_id: 1263685
rule_id: GdUDJO
version_id: e1TyjJv
url: https://semgrep.dev/playground/r/e1TyjJv/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings
origin: community
- id: scala.play.security.tainted-slick-sqli.tainted-slick-sqli
mode: taint
metadata:
references:
- https://scala-slick.org/doc/3.3.3/sql.html#splicing-literal-values
- https://scala-slick.org/doc/3.2.0/sql-to-slick.html#non-optimal-sql-code
category: security
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
technology:
- scala
- slick
- play
confidence: HIGH
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/scala.play.security.tainted-slick-sqli.tainted-slick-sqli
shortlink: https://sg.run/k9K2
semgrep.dev:
rule:
r_id: 18328
rv_id: 1263687
rule_id: GdUDWO
version_id: d6TyxJe
url: https://semgrep.dev/playground/r/d6TyxJe/scala.play.security.tainted-slick-sqli.tainted-slick-sqli
origin: community
message: Detected a tainted SQL statement. This could lead to SQL injection if variables
in the SQL statement are not properly sanitized. Avoid using using user input
for generating SQL strings.
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern: $REQ
- pattern-either:
- pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n"
- pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n"
- pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n"
- pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n"
- patterns:
- pattern: $PARAM
- pattern-either:
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action {
...
}
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) {
...
}
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async {
...
}
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) {
...
}
pattern-sinks:
- patterns:
- pattern-either:
- pattern: $MODEL.overrideSql(...)
- pattern: sql"..."
- pattern-inside: |
import slick.$DEPS
...
severity: ERROR
languages:
- scala
- id: go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check
patterns:
- pattern-inside: |
import ("github.com/gorilla/websocket")
...
- patterns:
- pattern-not-inside: |
$UPGRADER = websocket.Upgrader{..., CheckOrigin: $FN ,...}
...
- pattern-not-inside: |
$UPGRADER.CheckOrigin = $FN2
...
- pattern: |
$UPGRADER.Upgrade(...)
message: 'The Origin header in the HTTP WebSocket handshake is used to guarantee
that the connection accepted by the WebSocket is from a trusted origin domain.
Failure to enforce can lead to Cross Site Request Forgery (CSRF). As per "gorilla/websocket"
documentation: "A CheckOrigin function should carefully validate the request origin
to prevent cross-site request forgery."'
languages:
- go
severity: WARNING
metadata:
category: security
cwe:
- 'CWE-352: Cross-Site Request Forgery (CSRF)'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://pkg.go.dev/github.com/gorilla/websocket#Upgrader
technology:
- gorilla
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site Request Forgery (CSRF)
source: https://semgrep.dev/r/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check
shortlink: https://sg.run/xXpz
semgrep.dev:
rule:
r_id: 18430
rv_id: 1262914
rule_id: ReUKdz
version_id: qkTR7RP
url: https://semgrep.dev/playground/r/qkTR7RP/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check
origin: community
- id: javascript.aws-lambda.security.tainted-html-string.tainted-html-string
message: Detected user input flowing into a manually constructed HTML string. You
may be accidentally bypassing secure methods of rendering HTML by manually constructing
HTML and this could create a cross-site scripting vulnerability, which could let
attackers steal sensitive user data. To be sure this is safe, check that the HTML
is rendered safely. Otherwise, use templates which will safely render HTML instead.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
references:
- https://owasp.org/Top10/A03_2021-Injection
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-string.tainted-html-string
shortlink: https://sg.run/Lgqr
semgrep.dev:
rule:
r_id: 18483
rv_id: 1263112
rule_id: PeUxwW
version_id: DkTRbvp
url: https://semgrep.dev/playground/r/DkTRbvp/javascript.aws-lambda.security.tainted-html-string.tainted-html-string
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
exports.handler = function ($EVENT, ...) {
...
}
- pattern-inside: |
function $FUNC ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern-inside: |
$FUNC = function ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern: $EVENT
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: |
"$HTMLSTR" + $EXPR
- pattern: |
"$HTMLSTR".concat(...)
- pattern: $UTIL.format($HTMLSTR, ...)
- pattern: format($HTMLSTR, ...)
- metavariable-pattern:
metavariable: $HTMLSTR
language: generic
pattern: <$TAG ...
- patterns:
- pattern: |
`...${...}...`
- pattern-regex: |
.*<\w+.*
- pattern-not-inside: |
console.$LOG(...)
- id: python.aws-lambda.security.tainted-html-string.tainted-html-string
languages:
- python
severity: WARNING
message: Detected user input flowing into a manually constructed HTML string. You
may be accidentally bypassing secure methods of rendering HTML by manually constructing
HTML and this could create a cross-site scripting vulnerability, which could let
attackers steal sensitive user data. To be sure this is safe, check that the HTML
is rendered safely. Otherwise, use templates which will safely render HTML instead.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- aws-lambda
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-string.tainted-html-string
shortlink: https://sg.run/8zNy
semgrep.dev:
rule:
r_id: 18484
rv_id: 1263344
rule_id: JDUlwy
version_id: 7ZTE36K
url: https://semgrep.dev/playground/r/7ZTE36K/python.aws-lambda.security.tainted-html-string.tainted-html-string
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: '"$HTMLSTR" % ...'
- pattern: '"$HTMLSTR".format(...)'
- pattern: '"$HTMLSTR" + ...'
- pattern: f"$HTMLSTR{...}..."
- patterns:
- pattern-inside: |
$HTML = "$HTMLSTR"
...
- pattern-either:
- pattern: $HTML % ...
- pattern: $HTML.format(...)
- pattern: $HTML + ...
- metavariable-pattern:
metavariable: $HTMLSTR
language: generic
pattern: <$TAG ...
- pattern-not-inside: |
print(...)
- id: scala.lang.security.audit.io-source-ssrf.io-source-ssrf
patterns:
- pattern-either:
- pattern: Source.fromURL($URL,...)
- pattern: Source.fromURI($URL,...)
- pattern-inside: |
import scala.io.$SOURCE
...
- pattern-either:
- pattern-inside: |
def $FUNC(..., $URL: $T, ...) = $A {
...
}
- pattern-inside: |
def $FUNC(..., $URL: $T, ...) = {
...
}
message: A parameter being passed directly into `fromURL` most likely lead to SSRF.
This could allow an attacker to send data to their own server, potentially exposing
sensitive data sent with this request. They could also probe internal servers
or other resources that the server running this code can access. Do not allow
arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode
the correct host.
metadata:
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
- https://www.scala-lang.org/api/current/scala/io/Source$.html#fromURL(url:java.net.URL)(implicitcodec:scala.io.Codec):scala.io.BufferedSource
category: security
technology:
- scala
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/scala.lang.security.audit.io-source-ssrf.io-source-ssrf
shortlink: https://sg.run/Qbz4
semgrep.dev:
rule:
r_id: 18486
rv_id: 1263675
rule_id: GdUDOZ
version_id: 1QTypG9
url: https://semgrep.dev/playground/r/1QTypG9/scala.lang.security.audit.io-source-ssrf.io-source-ssrf
origin: community
languages:
- scala
severity: WARNING
- id: scala.lang.security.audit.scalac-debug.scalac-debug
patterns:
- pattern-either:
- pattern: scalacOptions ... "-Vdebug"
- pattern: scalacOptions ... "-Ydebug"
message: Scala applications built with `debug` set to true in production may leak
debug information to attackers. Debug mode also affects performance and reliability.
Remove it from configuration.
languages:
- generic
severity: WARNING
paths:
include:
- '*.sbt*'
metadata:
category: security
cwe:
- 'CWE-489: Active Debug Code'
owasp: A05:2021 - Security Misconfiguration
technology:
- scala
- sbt
references:
- https://docs.scala-lang.org/overviews/compiler-options/index.html
confidence: MEDIUM
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Active Debug Code
source: https://semgrep.dev/r/scala.lang.security.audit.scalac-debug.scalac-debug
shortlink: https://sg.run/QbGd
semgrep.dev:
rule:
r_id: 18686
rv_id: 946569
rule_id: JDUlE0
version_id: qkT4j0N
url: https://semgrep.dev/playground/r/qkT4j0N/scala.lang.security.audit.scalac-debug.scalac-debug
origin: community
- id: scala.play.security.tainted-html-response.tainted-html-response
mode: taint
metadata:
category: security
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
technology:
- scala
- play
confidence: MEDIUM
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/scala.play.security.tainted-html-response.tainted-html-response
shortlink: https://sg.run/BG96
semgrep.dev:
rule:
r_id: 18795
rv_id: 1263686
rule_id: 0oUwn2
version_id: vdT06yj
url: https://semgrep.dev/playground/r/vdT06yj/scala.play.security.tainted-html-response.tainted-html-response
origin: community
message: Detected a request with potential user-input going into an `Ok()` response.
This bypasses any view or template environments, including HTML escaping, which
may expose this application to cross-site scripting (XSS) vulnerabilities. Consider
using a view technology such as Twirl which automatically escapes HTML views.
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern: $REQ
- pattern-either:
- pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n"
- pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n"
- pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n"
- pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n"
- patterns:
- pattern: $PARAM
- pattern-either:
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action {
...
}
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) {
...
}
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async {
...
}
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) {
...
}
pattern-sanitizers:
- pattern-either:
- pattern: org.apache.commons.lang3.StringEscapeUtils.escapeHtml4(...)
- pattern: org.owasp.encoder.Encode.forHtml(...)
pattern-sinks:
- pattern-either:
- pattern: Html.apply(...)
- pattern: Ok(...).as(HTML)
- pattern: Ok(...).as(ContentTypes.HTML)
- patterns:
- pattern: Ok(...).as($CTYPE)
- metavariable-regex:
metavariable: $CTYPE
regex: '"[tT][eE][xX][tT]/[hH][tT][mM][lL]"'
- patterns:
- pattern: Ok(...).as($CTYPE)
- pattern-not: Ok(...).as("...")
- pattern-either:
- pattern-inside: |
def $FUNC(..., $URL: $T, ...) = $A {
...
}
- pattern-inside: |
def $FUNC(..., $URL: $T, ...) = {
...
}
severity: WARNING
languages:
- scala
- id: terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version
patterns:
- pattern-either:
- pattern: |
resource "aws_api_gateway_domain_name" $ANYTHING {
...
security_policy = "..."
...
}
- pattern: |
resource "aws_apigatewayv2_domain_name" $ANYTHING {
...
domain_name_configuration {...}
...
}
- pattern-not: |
resource "aws_api_gateway_domain_name" $ANYTHING {
...
security_policy = "TLS_1_2"
...
}
- pattern-not: |
resource "aws_apigatewayv2_domain_name" $ANYTHING {
...
domain_name_configuration {
...
security_policy = "TLS_1_2"
...
}
}
message: Detected AWS API Gateway to be using an insecure version of TLS. To fix
this issue make sure to set "security_policy" equal to "TLS_1_2".
languages:
- terraform
severity: WARNING
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
category: security
technology:
- aws
- terraform
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version
shortlink: https://sg.run/p98J
semgrep.dev:
rule:
r_id: 18818
rv_id: 1263726
rule_id: v8UOle
version_id: o5TbD8k
url: https://semgrep.dev/playground/r/o5TbD8k/terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version
origin: community
- id: php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv
patterns:
- pattern-either:
- pattern: openssl_encrypt($D, $M, $K, $FLAGS, "...",...);
- pattern: openssl_decrypt($D, $M, $K, $FLAGS, "...",...);
- metavariable-comparison:
metavariable: $M
comparison: re.match(".*-CBC",$M)
message: Static IV used with AES in CBC mode. Static IVs enable chosen-plaintext
attacks against encrypted data.
languages:
- php
severity: ERROR
metadata:
cwe:
- 'CWE-329: Generation of Predictable IV with CBC Mode'
references:
- https://csrc.nist.gov/publications/detail/sp/800-38a/final
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
technology:
- php
- openssl
category: security
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv
shortlink: https://sg.run/LgWJ
semgrep.dev:
rule:
r_id: 19039
rv_id: 1263295
rule_id: DbUGbE
version_id: JdTzxOD
url: https://semgrep.dev/playground/r/JdTzxOD/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv
origin: community
- id: scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode
patterns:
- pattern-inside: |
import pdi.jwt.$DEPS
...
- pattern-either:
- pattern: $JWT.encode($X, "...", ...)
- pattern: $JWT.decode($X, "...", ...)
- pattern: $JWT.decodeRawAll($X, "...", ...)
- pattern: $JWT.decodeRaw($X, "...", ...)
- pattern: $JWT.decodeAll($X, "...", ...)
- pattern: $JWT.validate($X, "...", ...)
- pattern: $JWT.isValid($X, "...", ...)
- pattern: $JWT.decodeJson($X, "...", ...)
- pattern: $JWT.decodeJsonAll($X, "...", ...)
- patterns:
- pattern-either:
- pattern: $JWT.encode($X, $KEY, ...)
- pattern: $JWT.decode($X, $KEY, ...)
- pattern: $JWT.decodeRawAll($X, $KEY, ...)
- pattern: $JWT.decodeRaw($X, $KEY, ...)
- pattern: $JWT.decodeAll($X, $KEY, ...)
- pattern: $JWT.validate($X, $KEY, ...)
- pattern: $JWT.isValid($X, $KEY, ...)
- pattern: $JWT.decodeJson($X, $KEY, ...)
- pattern: $JWT.decodeJsonAll($X, $KEY, ...)
- pattern: $JWT.encode($X, this.$KEY, ...)
- pattern: $JWT.decode($X, this.$KEY, ...)
- pattern: $JWT.decodeRawAll($X, this.$KEY, ...)
- pattern: $JWT.decodeRaw($X, this.$KEY, ...)
- pattern: $JWT.decodeAll($X, this.$KEY, ...)
- pattern: $JWT.validate($X, this.$KEY, ...)
- pattern: $JWT.isValid($X, this.$KEY, ...)
- pattern: $JWT.decodeJson($X, this.$KEY, ...)
- pattern: $JWT.decodeJsonAll($X, this.$KEY, ...)
- pattern-either:
- pattern-inside: |
class $CL {
...
$KEY = "..."
...
}
- pattern-inside: |
object $CL {
...
$KEY = "..."
...
}
- metavariable-pattern:
metavariable: $JWT
patterns:
- pattern-either:
- pattern: Jwt
- pattern: JwtArgonaut
- pattern: JwtCirce
- pattern: JwtJson4s
- pattern: JwtJson
- pattern: JwtUpickle
message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently
Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html
Consider using an appropriate security mechanism to protect the credentials (e.g.
keeping secrets in environment variables)'
languages:
- scala
severity: WARNING
metadata:
references:
- https://jwt-scala.github.io/jwt-scala/
category: security
cwe:
- 'CWE-522: Insufficiently Protected Credentials'
owasp:
- A02:2017 - Broken Authentication
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
technology:
- scala
confidence: HIGH
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode
shortlink: https://sg.run/8zE7
semgrep.dev:
rule:
r_id: 19040
rv_id: 1263669
rule_id: WAUdK0
version_id: o5TbDA8
url: https://semgrep.dev/playground/r/o5TbDA8/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode
origin: community
- id: scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled
patterns:
- pattern-either:
- pattern: |
$DF = DocumentBuilderFactory.newInstance(...)
...
$DB = $DF.newDocumentBuilder(...)
- patterns:
- pattern: $DB = DocumentBuilderFactory.newInstance(...)
- pattern-not-inside: |
...
$X = $DB.newDocumentBuilder(...)
- pattern: $DB = DocumentBuilderFactory.newInstance(...).newDocumentBuilder(...)
- pattern-not-inside: |
...
$DB.setXIncludeAware(true)
...
$DB.setNamespaceAware(true)
...
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
...
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
...
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
- pattern-not-inside: |
...
$DB.setXIncludeAware(true)
...
$DB.setNamespaceAware(true)
...
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
...
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
...
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
- pattern-not-inside: |
...
$DB.setXIncludeAware(true)
...
$DB.setNamespaceAware(true)
...
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
...
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
...
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
- pattern-not-inside: |
...
$DB.setXIncludeAware(true)
...
$DB.setNamespaceAware(true)
...
$DB.setFeature("http://xml.org/sax/features/external-general-entities", false)
...
$DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
...
$DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
message: Document Builder being instantiated without calling the `setFeature` functions
that are generally used for disabling entity processing. User controlled data
in XML Document builder can result in XML Internal Entity Processing vulnerabilities
like the disclosure of confidential data, denial of service, Server Side Request
Forgery (SSRF), port scanning. Make sure to disable entity processing functionality.
languages:
- scala
severity: WARNING
metadata:
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
category: security
technology:
- scala
confidence: HIGH
references:
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled
shortlink: https://sg.run/gRQn
semgrep.dev:
rule:
r_id: 19041
rv_id: 1263673
rule_id: 0oUwzP
version_id: X0TzyRq
url: https://semgrep.dev/playground/r/X0TzyRq/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled
origin: community
- id: scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled
patterns:
- pattern-either:
- pattern: $SR = new SAXReader(...)
- pattern: |
$SF = SAXParserFactory.newInstance(...)
...
$SR = $SF.newSAXParser(...)
- patterns:
- pattern: $SR = SAXParserFactory.newInstance(...)
- pattern-not-inside: |
...
$X = $SR.newSAXParser(...)
- pattern: $SR = SAXParserFactory.newInstance(...).newSAXParser(...)
- pattern: $SR = new SAXBuilder(...)
- pattern-not-inside: |
...
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
...
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
...
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
- pattern-not-inside: |
...
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
...
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
...
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
- pattern-not-inside: |
...
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
...
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
...
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
- pattern-not-inside: |
...
$SR.setFeature("http://xml.org/sax/features/external-general-entities", false)
...
$SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false)
...
$SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
message: XML processor being instantiated without calling the `setFeature` functions
that are generally used for disabling entity processing. User controlled data
in XML Parsers can result in XML Internal Entity Processing vulnerabilities like
the disclosure of confidential data, denial of service, Server Side Request Forgery
(SSRF), port scanning. Make sure to disable entity processing functionality.
languages:
- scala
severity: WARNING
metadata:
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
category: security
technology:
- scala
confidence: HIGH
references:
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled
shortlink: https://sg.run/QbYP
semgrep.dev:
rule:
r_id: 19042
rv_id: 1263678
rule_id: KxUrkq
version_id: rxTAKWY
url: https://semgrep.dev/playground/r/rxTAKWY/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled
origin: community
- id: scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled
patterns:
- pattern-not-inside: |
...
$XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false)
- pattern-either:
- pattern: $XMLFACTORY = XMLInputFactory.newFactory(...)
- pattern: $XMLFACTORY = XMLInputFactory.newInstance(...)
- pattern: $XMLFACTORY = new XMLInputFactory(...)
message: XMLInputFactory being instantiated without calling the setProperty functions
that are generally used for disabling entity processing. User controlled data
in XML Document builder can result in XML Internal Entity Processing vulnerabilities
like the disclosure of confidential data, denial of service, Server Side Request
Forgery (SSRF), port scanning. Make sure to disable entity processing functionality.
languages:
- scala
severity: WARNING
metadata:
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
category: security
technology:
- scala
confidence: HIGH
references:
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled
shortlink: https://sg.run/3BEb
semgrep.dev:
rule:
r_id: 19043
rv_id: 1263683
rule_id: qNUQ7w
version_id: xyTjzkA
url: https://semgrep.dev/playground/r/xyTjzkA/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled
origin: community
- id: scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass
patterns:
- pattern-either:
- pattern: X-Requested-With = "*"
- pattern: Csrf-Token = "..."
- pattern-inside: |
bypassHeaders {...
...
...}
- pattern-not-inside: |
{...
...
...blackList = [..."application/x-www-form-urlencoded"..."multipart/form-data"..."text/plain"...]
...
...}
- pattern-not-inside: |
{...
...
...blackList = [..."application/x-www-form-urlencoded"..."text/plain"..."multipart/form-data"...]
...
...}
- pattern-not-inside: |
{...
...
...blackList = [..."multipart/form-data"..."application/x-www-form-urlencoded"..."text/plain"...]
...
...}
- pattern-not-inside: |
{...
...
...blackList = [..."multipart/form-data"..."text/plain"..."application/x-www-form-urlencoded"...]
...
...}
- pattern-not-inside: |
{...
...
...blackList = [..."text/plain"..."application/x-www-form-urlencoded"..."multipart/form-data"...]
...
...}
- pattern-not-inside: |
{...
...
...blackList = [..."text/plain"..."multipart/form-data"..."application/x-www-form-urlencoded"...]
...
...}
message: "Possibly bypassable CSRF configuration found. CSRF is an attack that forces
an end user to execute unwanted actions on a web application in which they\u2019re
currently authenticated. Make sure that Content-Type black list is configured
and CORS filter is turned on."
languages:
- generic
severity: ERROR
paths:
include:
- '*.conf'
metadata:
references:
- https://www.playframework.com/documentation/2.8.x/Migration25#CSRF-changes
- https://owasp.org/www-community/attacks/csrf
cwe:
- 'CWE-352: Cross-Site Request Forgery (CSRF)'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
category: security
technology:
- scala
- play
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site Request Forgery (CSRF)
source: https://semgrep.dev/r/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass
shortlink: https://sg.run/4DEE
semgrep.dev:
rule:
r_id: 19044
rv_id: 1263684
rule_id: lBUyRR
version_id: O9Tpx53
url: https://semgrep.dev/playground/r/O9Tpx53/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass
origin: community
- id: terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version
pattern: |
resource "aws_elasticsearch_domain" $ANYTHING {
...
domain_endpoint_options {
...
enforce_https = true
tls_security_policy = "Policy-Min-TLS-1-0-2019-07"
...
}
...
}
message: Detected an AWS Elasticsearch domain using an insecure version of TLS.
To fix this, set "tls_security_policy" equal to "Policy-Min-TLS-1-2-2019-07".
languages:
- terraform
severity: WARNING
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
category: security
technology:
- aws
- terraform
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version
shortlink: https://sg.run/PYlq
semgrep.dev:
rule:
r_id: 19045
rv_id: 1263718
rule_id: YGUle7
version_id: DkTRbA5
url: https://semgrep.dev/playground/r/DkTRbA5/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version
origin: community
- id: javascript.express.security.express-insecure-template-usage.express-insecure-template-usage
message: User data from `$REQ` is being compiled into the template, which can lead
to a Server Side Template Injection (SSTI) vulnerability.
options:
interfile: true
metadata:
interfile: true
category: security
cwe:
- 'CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine'
owasp:
- A03:2021 - Injection
- A01:2017 - Injection
- A05:2025 - Injection
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html
technology:
- javascript
- typescript
- express
- pug
- jade
- dot
- ejs
- nunjucks
- lodash
- handlbars
- mustache
- hogan.js
- eta
- squirrelly
source_rule_url:
- https://github.com/github/codeql/blob/2ba2642c7ab29b9eedef33bcc2b8cd1d203d0c10/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/template-sinks.js
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage
shortlink: https://sg.run/b49v
semgrep.dev:
rule:
r_id: 19226
rv_id: 1263165
rule_id: EwUr9k
version_id: zyTb2eD
url: https://semgrep.dev/playground/r/zyTb2eD/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-propagators:
- pattern: $MODEL.$FIND($E).then((...,$S,...)=>{...})
from: $E
to: $S
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- pattern-either:
- patterns:
- pattern-either:
- pattern-inside: |
$PUG = require('pug')
...
- pattern-inside: |
import * as $PUG from 'pug'
...
- pattern-inside: |
$PUG = require('jade')
...
- pattern-inside: |
import * as $PUG from 'jade'
...
- pattern-either:
- pattern: $PUG.compile(...)
- pattern: $PUG.compileClient(...)
- pattern: $PUG.compileClientWithDependenciesTracked(...)
- pattern: $PUG.render(...)
- patterns:
- pattern-either:
- pattern-inside: |
$PUG = require('dot')
...
- pattern-inside: |
import * as $PUG from 'dot'
...
- pattern-either:
- pattern: $PUG.template(...)
- pattern: $PUG.compile(...)
- patterns:
- pattern-either:
- pattern-inside: |
$PUG = require('ejs')
...
- pattern-inside: |
import * as $PUG from 'ejs'
...
- pattern-either:
- pattern: $PUG.render(...)
- patterns:
- pattern-either:
- pattern-inside: |
$PUG = require('nunjucks')
...
- pattern-inside: |
import * as $PUG from 'nunjucks'
...
- pattern-either:
- pattern: $PUG.renderString(...)
- patterns:
- pattern-either:
- pattern-inside: |
$PUG = require('lodash')
...
- pattern-inside: |
import * as $PUG from 'lodash'
...
- pattern-either:
- pattern: $PUG.template(...)
- patterns:
- pattern-either:
- pattern-inside: |
$PUG = require('mustache')
...
- pattern-inside: |
import * as $PUG from 'mustache'
...
- pattern-inside: |
$PUG = require('eta')
...
- pattern-inside: |
import * as $PUG from 'eta'
...
- pattern-inside: |
$PUG = require('squirrelly')
...
- pattern-inside: |
import * as $PUG from 'squirrelly'
...
- pattern-either:
- pattern: $PUG.render(...)
- patterns:
- pattern-either:
- pattern-inside: |
$PUG = require('hogan.js')
...
- pattern-inside: |
import * as $PUG from 'hogan.js'
...
- pattern-inside: |
$PUG = require('handlebars')
...
- pattern-inside: |
import * as $PUG from 'handlebars'
...
- pattern-either:
- pattern: $PUG.compile(...)
- id: python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled
patterns:
- pattern: jinja2.Environment(... , autoescape=$VAL, ...)
- pattern-not: jinja2.Environment(... , autoescape=True, ...)
- pattern-not: jinja2.Environment(... , autoescape=jinja2.select_autoescape(...),
...)
- focus-metavariable: $VAL
fix: |
True
message: Detected a Jinja2 environment with 'autoescaping' disabled. This is dangerous
if you are rendering to a browser because this allows for cross-site scripting
(XSS) attacks. If you are in a web context, enable 'autoescaping' by setting 'autoescape=True.'
You may also consider using 'jinja2.select_autoescape()' to only enable automatic
escaping for certain file extensions.
metadata:
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html
cwe:
- 'CWE-116: Improper Encoding or Escaping of Output'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://jinja.palletsprojects.com/en/2.11.x/api/#basics
category: security
technology:
- jinja2
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Encoding
source: https://semgrep.dev/r/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled
shortlink: https://sg.run/L2L7
semgrep.dev:
rule:
r_id: 20039
rv_id: 1263448
rule_id: QrU1Xg
version_id: gETB7oN
url: https://semgrep.dev/playground/r/gETB7oN/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled
origin: community
languages:
- python
severity: WARNING
- id: python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled
patterns:
- pattern-not: jinja2.Environment(..., autoescape=$VAL, ...)
- pattern: jinja2.Environment(...)
fix-regex:
regex: (.*)\)
replacement: \1, autoescape=True)
message: Detected a Jinja2 environment without autoescaping. Jinja2 does not autoescape
by default. This is dangerous if you are rendering to a browser because this allows
for cross-site scripting (XSS) attacks. If you are in a web context, enable autoescaping
by setting 'autoescape=True.' You may also consider using 'jinja2.select_autoescape()'
to only enable automatic escaping for certain file extensions.
metadata:
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html
cwe:
- 'CWE-116: Improper Encoding or Escaping of Output'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://jinja.palletsprojects.com/en/2.11.x/api/#basics
category: security
technology:
- jinja2
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Encoding
source: https://semgrep.dev/r/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled
shortlink: https://sg.run/8kY4
semgrep.dev:
rule:
r_id: 20040
rv_id: 1263449
rule_id: 3qULRx
version_id: QkTGqje
url: https://semgrep.dev/playground/r/QkTGqje/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled
origin: community
languages:
- python
severity: WARNING
- id: ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include
mode: search
paths:
include:
- '*.erb'
patterns:
- pattern: |
params[...]
- pattern-inside: |
render :file => ...
message: Found request parameters in a call to `render` in a dynamic context. This
can allow end users to request arbitrary local files which may result in leaking
sensitive information persisted on disk.
languages:
- generic
severity: WARNING
metadata:
technology:
- ruby
- rails
category: security
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb
references:
- https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion
- https://github.com/presidentbeef/brakeman/blob/f74cb53ead47f0af821d98b5b41e16d63100c240/test/apps/rails2/app/views/home/test_render.html.erb
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include
shortlink: https://sg.run/3QWl
semgrep.dev:
rule:
r_id: 20043
rv_id: 1263651
rule_id: JDUokO
version_id: QkTGq9X
url: https://semgrep.dev/playground/r/QkTGq9X/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include
origin: community
- id: ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include
mode: taint
pattern-sources:
- patterns:
- pattern: params[...]
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
render ..., file: $X
- pattern: |
render ..., inline: $X
- pattern: |
render ..., template: $X
- pattern: |
render ..., action: $X
- pattern: |
render $X, ...
- focus-metavariable: $X
pattern-sanitizers:
- patterns:
- pattern: $MAP[...]
- metavariable-pattern:
metavariable: $MAP
patterns:
- pattern-not-regex: params
- pattern: File.basename(...)
message: Found request parameters in a call to `render`. This can allow end users
to request arbitrary local files which may result in leaking sensitive information
persisted on disk. Where possible, avoid letting users specify template paths
for `render`. If you must allow user input, use an allow-list of known templates
or normalize the user-supplied value with `File.basename(...)`.
languages:
- ruby
severity: WARNING
metadata:
technology:
- ruby
- rails
category: security
cwe:
- 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path
Traversal'')'
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb
references:
- https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion
- https://github.com/presidentbeef/brakeman/blob/f74cb53/test/apps/rails2/app/controllers/home_controller.rb#L48-L60
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
vulnerability_class:
- Path Traversal
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include
shortlink: https://sg.run/Jw8Z
semgrep.dev:
rule:
r_id: 20046
rv_id: 1409407
rule_id: ReU2pZ
version_id: K3TgANN
url: https://semgrep.dev/playground/r/K3TgANN/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include
origin: community
- id: ruby.rails.security.brakeman.check-secrets.check-secrets
patterns:
- pattern: $VAR = "$VALUE"
- metavariable-regex:
metavariable: $VAR
regex: (?i)password|secret|(rest_auth_site|api)_key$
- metavariable-regex:
metavariable: $VALUE
regex: .+
message: Found a Brakeman-style secret - a variable with the name password/secret/api_key/rest_auth_site_key
and a non-empty string literal value.
languages:
- ruby
severity: WARNING
metadata:
technology:
- ruby
- rails
category: security
cwe:
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_secrets.rb
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
- https://github.com/presidentbeef/brakeman/blob/3f5d5d5f00864cdf7769c50f5bd26f1769a4ba75/test/apps/rails3.1/app/controllers/users_controller.rb
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-secrets.check-secrets
shortlink: https://sg.run/5ZKl
semgrep.dev:
rule:
r_id: 20047
rv_id: 1263659
rule_id: AbUNqO
version_id: A8TgdBv
url: https://semgrep.dev/playground/r/A8TgdBv/ruby.rails.security.brakeman.check-secrets.check-secrets
origin: community
- id: ruby.rails.security.brakeman.check-send-file.check-send-file
mode: taint
pattern-sources:
- pattern-either:
- pattern: |
cookies[...]
- patterns:
- pattern: |
cookies. ... .$PROPERTY[...]
- metavariable-regex:
metavariable: $PROPERTY
regex: (?!signed|encrypted)
- pattern: |
params[...]
- pattern: |
request.env[...]
pattern-sinks:
- patterns:
- pattern: |
send_file ...
message: Allowing user input to `send_file` allows a malicious user to potentially
read arbitrary files from the server. Avoid accepting user input in `send_file`
or normalize with `File.basename(...)`
languages:
- ruby
severity: ERROR
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_send_file.rb
category: security
cwe:
- 'CWE-73: External Control of File Name or Path'
owasp:
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
technology:
- ruby
- rails
references:
- https://owasp.org/www-community/attacks/Path_Traversal
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-send-file.check-send-file
shortlink: https://sg.run/GbY1
semgrep.dev:
rule:
r_id: 20048
rv_id: 1263660
rule_id: BYUKbl
version_id: BjTkZRj
url: https://semgrep.dev/playground/r/BjTkZRj/ruby.rails.security.brakeman.check-send-file.check-send-file
origin: community
- id: scala.lang.security.audit.tainted-sql-string.tainted-sql-string
languages:
- scala
severity: ERROR
mode: taint
message: User data flows into this manually-constructed SQL string. User data can
be safely inserted into SQL strings using prepared statements or an object-relational
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
injection, which could let an attacker steal or manipulate data from the database.
Instead, use prepared statements (`connection.PreparedStatement`) or a safe library.
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html
category: security
technology:
- scala
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/scala.lang.security.audit.tainted-sql-string.tainted-sql-string
shortlink: https://sg.run/ALD6
semgrep.dev:
rule:
r_id: 20050
rv_id: 1263682
rule_id: WAUY8B
version_id: w8TRoO6
url: https://semgrep.dev/playground/r/w8TRoO6/scala.lang.security.audit.tainted-sql-string.tainted-sql-string
origin: community
pattern-sources:
- patterns:
- pattern: $PARAM
- pattern-either:
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = {
...
}
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = $A {
...
}
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = $A(...) {
...
}
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: |
"$SQLSTR" + ...
- pattern: |
"$SQLSTR".format(...)
- patterns:
- pattern-inside: |
$SB = new StringBuilder("$SQLSTR");
...
- pattern: $SB.append(...)
- patterns:
- pattern-inside: |
$VAR = "$SQLSTR"
...
- pattern: $VAR += ...
- metavariable-regex:
metavariable: $SQLSTR
regex: (?i)(select|delete|insert|create|update|alter|drop)\b
- patterns:
- pattern-either:
- pattern: s"..."
- pattern: f"..."
- pattern-regex: |
.*\b(?i)(select|delete|insert|create|update|alter|drop)\b.*
- pattern-not-inside: println(...)
- pattern-not-inside: throw new $EXCEPTION(...)
pattern-sanitizers:
- pattern-either:
- patterns:
- pattern-either:
- pattern: $LOGGER.$METHOD(...)
- pattern: $LOGGER(...)
- metavariable-regex:
metavariable: $LOGGER
regex: (i?)log.*
- patterns:
- pattern: $LOGGER.$METHOD(...)
- metavariable-regex:
metavariable: $METHOD
regex: (i?)(trace|info|warn|warning|warnToError|error|debug)
- id: scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request
languages:
- scala
severity: ERROR
mode: taint
message: User data flows into this manually-constructed SQL string. User data can
be safely inserted into SQL strings using prepared statements or an object-relational
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
injection, which could let an attacker steal or manipulate data from the database.
Instead, use prepared statements (`connection.PreparedStatement`) or a safe library.
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html
category: security
technology:
- scala
- play
confidence: HIGH
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request
shortlink: https://sg.run/BeW9
semgrep.dev:
rule:
r_id: 20051
rv_id: 1263688
rule_id: 0oUpon
version_id: ZRTKAoG
url: https://semgrep.dev/playground/r/ZRTKAoG/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request
origin: community
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern: $REQ
- pattern-either:
- pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n"
- pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n"
- pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n"
- pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n"
- patterns:
- pattern: $PARAM
- pattern-either:
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action {
...
}
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) {
...
}
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async {
...
}
- pattern-inside: |
def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) {
...
}
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: |
"$SQLSTR" + ...
- pattern: |
"$SQLSTR".format(...)
- patterns:
- pattern-inside: |
$SB = new StringBuilder("$SQLSTR");
...
- pattern: $SB.append(...)
- patterns:
- pattern-inside: |
$VAR = "$SQLSTR"
...
- pattern: $VAR += ...
- metavariable-regex:
metavariable: $SQLSTR
regex: (?i)(select|delete|insert|create|update|alter|drop)\b
- patterns:
- pattern: s"..."
- pattern-regex: |
.*\b(?i)(select|delete|insert|create|update|alter|drop)\b.*
- pattern-not-inside: println(...)
- id: yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file
patterns:
- pattern: |
$KEY: $VALUE
- pattern-inside: |
data: ...
- pattern-inside: |
kind: Secret
...
- metavariable-regex:
metavariable: $VALUE
regex: (?i)^[aA-zZ0-9+/]+={0,2}$
- metavariable-analysis:
analyzer: entropy
metavariable: $VALUE
message: 'Secrets ($VALUE) should not be stored in infrastructure as code files.
Use an alternative such as Bitnami Sealed Secrets or KSOPS to encrypt Kubernetes
Secrets. '
metadata:
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
category: security
technology:
- kubernetes
references:
- https://kubernetes.io/docs/concepts/configuration/secret/
- https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/0/CTR_Kubernetes_Hardening_Guidance_1.1_20220315.PDF
- https://docs.gitlab.com/ee/user/clusters/agent/gitops/secrets_management.html
- https://www.cncf.io/blog/2021/04/22/revealing-the-secrets-of-kubernetes-secrets/
- https://github.com/bitnami-labs/sealed-secrets
- https://www.cncf.io/blog/2022/01/25/secrets-management-essential-when-using-kubernetes/
- https://blog.oddbit.com/post/2021-03-09-getting-started-with-ksops/
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file
shortlink: https://sg.run/KyL6
semgrep.dev:
rule:
r_id: 20055
rv_id: 1263942
rule_id: YGUYEb
version_id: xyTjz5B
url: https://semgrep.dev/playground/r/xyTjz5B/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file
origin: community
languages:
- yaml
severity: WARNING
- id: dockerfile.security.last-user-is-root.last-user-is-root
patterns:
- pattern: USER root
- pattern-not-inside:
patterns:
- pattern: |
USER root
...
USER $X
- metavariable-pattern:
metavariable: $X
patterns:
- pattern-not: root
message: The last user in the container is 'root'. This is a security hazard because
if an attacker gains control of the container they will have root access. Switch
back to another user after running commands as 'root'.
severity: ERROR
languages:
- dockerfile
metadata:
cwe:
- 'CWE-269: Improper Privilege Management'
source-rule-url: https://github.com/hadolint/hadolint/wiki/DL3002
references:
- https://github.com/hadolint/hadolint/wiki/DL3002
category: security
technology:
- dockerfile
confidence: MEDIUM
owasp:
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/dockerfile.security.last-user-is-root.last-user-is-root
shortlink: https://sg.run/5Z43
semgrep.dev:
rule:
r_id: 20147
rv_id: 1262658
rule_id: ReU2n5
version_id: 6xT29Eg
url: https://semgrep.dev/playground/r/6xT29Eg/dockerfile.security.last-user-is-root.last-user-is-root
origin: community
- id: dockerfile.security.missing-user.missing-user
patterns:
- pattern: |
CMD $...VARS
- pattern-not-inside: |
USER $USER
...
- pattern-not-inside: |
HEALTHCHECK ... CMD ...
fix: |
USER non-root
CMD $...VARS
message: By not specifying a USER, a program in the container may run as 'root'.
This is a security hazard. If an attacker can control a process running as root,
they may have control over the container. Ensure that the last USER in a Dockerfile
is a USER other than 'root'.
severity: ERROR
languages:
- dockerfile
metadata:
cwe:
- 'CWE-250: Execution with Unnecessary Privileges'
category: security
technology:
- dockerfile
confidence: MEDIUM
owasp:
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/dockerfile.security.missing-user.missing-user
shortlink: https://sg.run/Gbvn
semgrep.dev:
rule:
r_id: 20148
rv_id: 1262660
rule_id: AbUN06
version_id: zyTb2n2
url: https://semgrep.dev/playground/r/zyTb2n2/dockerfile.security.missing-user.missing-user
origin: community
- id: javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config
message: Prefer Argon2id where possible. Per RFC9016, section 4 IETF recommends
selecting Argon2id unless you can guarantee an adversary has no direct access
to the computing environment.
metadata:
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
- https://eprint.iacr.org/2016/759.pdf
- https://www.cs.tau.ac.il/~tromer/papers/cache-joc-20090619.pdf
- https://datatracker.ietf.org/doc/html/rfc9106#section-4
category: security
cwe:
- 'CWE-916: Use of Password Hash With Insufficient Computational Effort'
technology:
- argon2
- cryptography
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
impact: LOW
likelihood: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config
shortlink: https://sg.run/ALq4
semgrep.dev:
rule:
r_id: 20150
rv_id: 1263103
rule_id: DbU2X8
version_id: qkTR7Jk
url: https://semgrep.dev/playground/r/qkTR7Jk/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-inside: |
$ARGON = require('argon2');
...
- pattern: |
{type: ...}
pattern-sinks:
- patterns:
- pattern: |
$Y
- pattern-inside: |
$ARGON.hash(...,$Y)
pattern-sanitizers:
- patterns:
- pattern: '{type: $ARGON.argon2id}'
- id: ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling
patterns:
- pattern-either:
- patterns:
- pattern: |
:$KEY => "$LITERAL"
- pattern-inside: |
ActionController::Base.session = {...}
- pattern: |
$RAILS::Application.config.$KEY = "$LITERAL"
- pattern: |
Rails.application.config.$KEY = "$LITERAL"
- metavariable-regex:
metavariable: $KEY
regex: ^secret(_(token|key_base))?$
message: Found a string literal assignment to a Rails session secret `$KEY`. Do
not commit secret values to source control! Any user in possession of this value
may falsify arbitrary session data in your application. Read this value from an
environment variable, KMS, or file on disk outside of source control.
languages:
- ruby
severity: WARNING
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_session_settings.rb
category: security
cwe:
- 'CWE-540: Inclusion of Sensitive Information in Source Code'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
technology:
- ruby
- rails
references:
- https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/06-Session_Management_Testing/02-Testing_for_Cookies_Attributes
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails4_with_engines/config/initializers/secret_token.rb
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3/config/initializers/secret_token.rb
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling
shortlink: https://sg.run/KyJd
semgrep.dev:
rule:
r_id: 20155
rv_id: 1263656
rule_id: lBUX1r
version_id: 5PTo1ZY
url: https://semgrep.dev/playground/r/5PTo1ZY/ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling
origin: community
- id: ruby.rails.security.brakeman.check-regex-dos.check-regex-dos
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
cookies[...]
- patterns:
- pattern: |
cookies. ... .$PROPERTY[...]
- metavariable-regex:
metavariable: $PROPERTY
regex: (?!signed|encrypted)
- pattern: |
params[...]
- pattern: |
request.env[...]
- patterns:
- pattern: $Y
- pattern-either:
- pattern-inside: |
$RECORD.read_attribute($Y)
- pattern-inside: |
$RECORD[$Y]
- metavariable-regex:
metavariable: $RECORD
regex: '[A-Z][a-z]+'
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: $Y
- pattern-inside: |
/...#{...}.../
- patterns:
- pattern: $Y
- pattern-inside: |
Regexp.new(...)
message: Found a potentially user-controllable argument in the construction of a
regular expressions. This may result in excessive resource consumption when applied
to certain inputs, or when the user is allowed to control the match target. Avoid
allowing users to specify regular expressions processed by the server. If you
must support user-controllable input in a regular expression, use an allow-list
to restrict the expressions users may supply to limit catastrophic backtracking.
languages:
- ruby
severity: ERROR
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_regex_dos.rb
category: security
cwe:
- 'CWE-1333: Inefficient Regular Expression Complexity'
owasp:
- A03:2017 - Sensitive Data Exposure
technology:
- ruby
- rails
references:
- https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Denial-of-Service (DoS)
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos
shortlink: https://sg.run/qZwx
semgrep.dev:
rule:
r_id: 20156
rv_id: 1409406
rule_id: YGUY4R
version_id: 0bTG0WO
url: https://semgrep.dev/playground/r/0bTG0WO/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos
origin: community
- id: ruby.rails.security.brakeman.check-before-filter.check-before-filter
mode: search
patterns:
- pattern-either:
- pattern: |
skip_filter ..., :except => $ARGS
- pattern: |
skip_before_filter ..., :except => $ARGS
- pattern: |
skip_before_action ..., :except => $ARGS
message: 'Disabled-by-default Rails controller checks make it much easier to introduce
access control mistakes. Prefer an allowlist approach with `:only => [...]` rather
than `except: => [...]`'
languages:
- ruby
severity: ERROR
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_skip_before_filter.rb
category: security
cwe:
- 'CWE-284: Improper Access Control'
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
technology:
- ruby
- rails
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-before-filter.check-before-filter
shortlink: https://sg.run/O4Zn
semgrep.dev:
rule:
r_id: 20531
rv_id: 1263649
rule_id: wdUkBP
version_id: 8KT5rDy
url: https://semgrep.dev/playground/r/8KT5rDy/ruby.rails.security.brakeman.check-before-filter.check-before-filter
origin: community
- id: ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion
mode: search
patterns:
- pattern: |
if request.get?
...
else
...
end
- pattern-not-inside: |
if ...
elsif ...
...
end
message: Found an improperly constructed control flow block with `request.get?`.
Rails will route HEAD requests as GET requests but they will fail the `request.get?`
check, potentially causing unexpected behavior unless an `elif` condition is used.
languages:
- ruby
severity: ERROR
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_verb_confusion.rb
category: security
cwe:
- 'CWE-650: Trusting HTTP Permission Methods on the Server Side'
owasp:
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
technology:
- ruby
- rails
references:
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/accounts_controller.rb
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion
shortlink: https://sg.run/eJ6y
semgrep.dev:
rule:
r_id: 20532
rv_id: 1263652
rule_id: x8UdDE
version_id: 3ZT4X82
url: https://semgrep.dev/playground/r/3ZT4X82/ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion
origin: community
- id: ruby.rails.security.brakeman.check-sql.check-sql
mode: taint
pattern-sources:
- pattern-either:
- pattern: |
cookies[...]
- patterns:
- pattern: |
cookies. ... .$PROPERTY[...]
- metavariable-regex:
metavariable: $PROPERTY
regex: (?!signed|encrypted)
- pattern: |
params[...]
- pattern: |
request.env[...]
pattern-sanitizers:
- patterns:
- pattern-either:
- patterns:
- pattern: $X
- pattern-either:
- pattern-inside: |
:$KEY => $X
- pattern-inside: |
["...",$X,...]
- pattern: |
params[...].to_i
- pattern: |
params[...].to_f
- patterns:
- pattern: |
params[...] ? $A : $B
- metavariable-pattern:
metavariable: $A
patterns:
- pattern-not: |
params[...]
- metavariable-pattern:
metavariable: $B
patterns:
- pattern-not: |
params[...]
pattern-sinks:
- patterns:
- pattern: $X
- pattern-not-inside: |
$P.where("...",...)
- pattern-not-inside: |
$P.where(:$KEY => $VAL,...)
- pattern-either:
- pattern-inside: |
$P.$M(...)
- pattern-inside: |
$P.$M("...",...)
- pattern-inside: |
class $P < ActiveRecord::Base
...
end
- metavariable-regex:
metavariable: $M
regex: (where|find|first|last|select|minimum|maximum|calculate|sum|average)
message: Found potential SQL injection due to unsafe SQL query construction via
$X. Where possible, prefer parameterized queries.
languages:
- ruby
severity: ERROR
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_sql.rb
category: security
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
technology:
- ruby
- rails
references:
- https://owasp.org/www-community/attacks/SQL_Injection
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/product.rb
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-sql.check-sql
shortlink: https://sg.run/vpgb
semgrep.dev:
rule:
r_id: 20533
rv_id: 1263661
rule_id: OrUv2z
version_id: DkTRbE4
url: https://semgrep.dev/playground/r/DkTRbE4/ruby.rails.security.brakeman.check-sql.check-sql
origin: community
- id: ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods
mode: taint
pattern-sources:
- pattern-either:
- pattern: |
cookies[...]
- patterns:
- pattern: |
cookies. ... .$PROPERTY[...]
- metavariable-regex:
metavariable: $PROPERTY
regex: (?!signed|encrypted)
- pattern: |
params[...]
- pattern: |
request.env[...]
pattern-sinks:
- patterns:
- pattern: $X
- pattern-either:
- pattern-inside: |
$X. ... .to_proc
- patterns:
- pattern-inside: |
$Y.method($Z)
- focus-metavariable: $Z
- patterns:
- pattern-inside: |
$Y.tap($Z)
- focus-metavariable: $Z
- patterns:
- pattern-inside: |
$Y.tap{ |$ANY| $Z }
- focus-metavariable: $Z
message: Found user-controllable input to a reflection method. This may allow a
user to alter program behavior and potentially execute arbitrary instructions
in the context of the process. Do not provide arbitrary user input to `tap`, `method`,
or `to_proc`
languages:
- ruby
severity: ERROR
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection_methods.rb
category: security
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
technology:
- ruby
- rails
references:
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/groups_controller.rb
cwe2022-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods
shortlink: https://sg.run/dPYd
semgrep.dev:
rule:
r_id: 20534
rv_id: 1263662
rule_id: eqUZ2Q
version_id: WrTqKLA
url: https://semgrep.dev/playground/r/WrTqKLA/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods
origin: community
- id: ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase
message: Found the use of an hardcoded passphrase for RSA. The passphrase can be
easily discovered, and therefore should not be stored in source-code. It is recommended
to remove the passphrase from source-code, and use system environment variables
or a restricted configuration file.
languages:
- ruby
severity: WARNING
metadata:
technology:
- ruby
- secrets
category: security
references:
- https://cwe.mitre.org/data/definitions/522.html
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase
shortlink: https://sg.run/xPEe
semgrep.dev:
rule:
r_id: 20730
rv_id: 1263607
rule_id: bwULyN
version_id: K3TKkEo
url: https://semgrep.dev/playground/r/K3TKkEo/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase
origin: community
patterns:
- pattern-either:
- pattern: OpenSSL::PKey::RSA.new(..., '...')
- pattern: OpenSSL::PKey::RSA.new(...).to_pem(..., '...')
- pattern: OpenSSL::PKey::RSA.new(...).export(..., '...')
- patterns:
- pattern-inside: |
$OPENSSL = OpenSSL::PKey::RSA.new(...)
...
- pattern-either:
- pattern: |
$OPENSSL.export(...,'...')
- pattern: |
$OPENSSL.to_pem(...,'...')
- patterns:
- pattern-either:
- patterns:
- pattern-inside: |
$ASSIGN = '...'
...
- pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN)
- patterns:
- pattern-inside: |
def $METHOD1(...)
...
$ASSIGN = '...'
...
end
...
def $METHOD2(...)
...
end
- pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN)
- patterns:
- pattern-inside: |
$ASSIGN = '...'
...
def $METHOD(...)
$OPENSSL = OpenSSL::PKey::RSA.new(...)
...
end
...
- pattern-either:
- pattern: $OPENSSL.export(...,$ASSIGN)
- pattern: $OPENSSL.to_pem(...,$ASSIGN)
- patterns:
- pattern-inside: |
def $METHOD1(...)
...
$OPENSSL = OpenSSL::PKey::RSA.new(...)
...
$ASSIGN = '...'
...
end
...
- pattern-either:
- pattern: $OPENSSL.export(...,$ASSIGN)
- pattern: $OPENSSL.to_pem(...,$ASSIGN)
- patterns:
- pattern-inside: |
def $METHOD1(...)
...
$ASSIGN = '...'
...
end
...
def $METHOD2(...)
...
$OPENSSL = OpenSSL::PKey::RSA.new(...)
...
end
...
- pattern-either:
- pattern: $OPENSSL.export(...,$ASSIGN)
- pattern: $OPENSSL.to_pem(...,$ASSIGN)
- id: ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size
message: The RSA key size $SIZE is insufficent by NIST standards. It is recommended
to use a key length of 2048 or higher.
languages:
- ruby
severity: WARNING
metadata:
technology:
- ruby
category: security
references:
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size
shortlink: https://sg.run/O4Re
semgrep.dev:
rule:
r_id: 20731
rv_id: 1263608
rule_id: NbUe4N
version_id: qkTR76v
url: https://semgrep.dev/playground/r/qkTR76v/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size
origin: community
patterns:
- pattern-either:
- pattern: OpenSSL::PKey::RSA.generate($SIZE,...)
- pattern: OpenSSL::PKey::RSA.new($SIZE, ...)
- patterns:
- pattern-either:
- patterns:
- pattern-inside: |
$ASSIGN = $SIZE
...
- pattern-either:
- pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...)
- pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...)
- patterns:
- pattern-inside: |
def $METHOD1(...)
...
$ASSIGN = $SIZE
...
end
...
- pattern-either:
- pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...)
- pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...)
- metavariable-comparison:
metavariable: $SIZE
comparison: $SIZE < 2048
- id: ruby.rails.security.brakeman.check-redirect-to.check-redirect-to
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: params
- pattern: cookies
- pattern: request.env
- pattern: url_for(params[...],...,:only_path => false,...)
pattern-sanitizers:
- patterns:
- pattern-either:
- patterns:
- pattern: |
$F(...)
- metavariable-pattern:
metavariable: $F
patterns:
- pattern-not-regex: (params|url_for|cookies|request.env|permit|redirect_to)
- pattern: |
params.merge! :only_path => true
...
- pattern: |
params.slice(...)
...
- pattern: |
redirect_to [...]
- patterns:
- pattern: |
$MODEL. ... .$M(...)
...
- metavariable-regex:
metavariable: $MODEL
regex: '[A-Z]\w+'
- metavariable-regex:
metavariable: $M
regex: (all|create|find|find_by|find_by_sql|first|last|new|from|group|having|joins|lock|order|reorder|select|where|take)
- patterns:
- pattern: |
params.$UNSAFE_HASH.merge(...,:only_path => true,...)
...
- metavariable-regex:
metavariable: $UNSAFE_HASH
regex: to_unsafe_h(ash)?
- patterns:
- pattern: params.permit(...,$X,...)
- metavariable-pattern:
metavariable: $X
patterns:
- pattern-not-regex: (host|port|(sub)?domain)
pattern-sinks:
- patterns:
- pattern: $X
- pattern-inside: |
redirect_to $X, ...
- pattern-not-regex: params\.\w+(?<!permit)\(.*?\)
message: Found potentially unsafe handling of redirect behavior $X. Do not pass
`params` to `redirect_to` without the `:only_path => true` hash value.
languages:
- ruby
severity: WARNING
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_redirect.rb
category: security
cwe:
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
technology:
- ruby
- rails
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Open Redirect
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to
shortlink: https://sg.run/eJNX
semgrep.dev:
rule:
r_id: 20732
rv_id: 1263657
rule_id: kxUOJ6
version_id: GxTke14
url: https://semgrep.dev/playground/r/GxTke14/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to
origin: community
- id: ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection
mode: taint
pattern-sources:
- pattern-either:
- pattern: |
cookies[...]
- patterns:
- pattern: |
cookies. ... .$PROPERTY[...]
- metavariable-regex:
metavariable: $PROPERTY
regex: (?!signed|encrypted)
- pattern: |
params[...]
- pattern: |
request.env[...]
pattern-sinks:
- patterns:
- pattern: $X
- pattern-either:
- pattern-inside: |
$X.constantize
- pattern-inside: |
$X. ... .safe_constantize
- pattern-inside: |
const_get(...)
- pattern-inside: |
qualified_const_get(...)
message: Found user-controllable input to Ruby reflection functionality. This allows
a remote user to influence runtime behavior, up to and including arbitrary remote
code execution. Do not provide user-controllable input to reflection functionality.
Do not call symbol conversion on user-controllable input.
languages:
- ruby
severity: ERROR
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection.rb
category: security
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
technology:
- ruby
- rails
references:
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails2/app/controllers/application_controller.rb
cwe2022-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection
shortlink: https://sg.run/vpEX
semgrep.dev:
rule:
r_id: 20733
rv_id: 1263663
rule_id: wdUkYA
version_id: 0bTKzn8
url: https://semgrep.dev/playground/r/0bTKzn8/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection
origin: community
- id: ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find
mode: taint
pattern-sources:
- pattern-either:
- pattern: |
cookies[...]
- patterns:
- pattern: |
cookies. ... .$PROPERTY[...]
- metavariable-regex:
metavariable: $PROPERTY
regex: (?!signed|encrypted)
- pattern: |
params[...]
- pattern: |
request.env[...]
pattern-sinks:
- patterns:
- pattern-either:
- pattern: $MODEL.find(...)
- pattern: $MODEL.find_by_id(...)
- pattern: $MODEL.find_by_id!(...)
- metavariable-regex:
metavariable: $MODEL
regex: '[A-Z]\S+'
message: Found an unscoped `find(...)` with user-controllable input. If the ActiveRecord
model being searched against is sensitive, this may lead to Insecure Direct Object
Reference (IDOR) behavior and allow users to read arbitrary records. Scope the
find to the current user, e.g. `current_user.accounts.find(params[:id])`.
languages:
- ruby
severity: WARNING
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unscoped_find.rb
category: security
cwe:
- 'CWE-639: Authorization Bypass Through User-Controlled Key'
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
technology:
- ruby
- rails
references:
- https://brakemanscanner.org/docs/warning_types/unscoped_find/
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/controllers/users_controller.rb
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find
shortlink: https://sg.run/dPbP
semgrep.dev:
rule:
r_id: 20734
rv_id: 1263664
rule_id: x8Ud6d
version_id: K3TKkxZ
url: https://semgrep.dev/playground/r/K3TKkxZ/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find
origin: community
- id: ruby.rails.security.brakeman.check-validation-regex.check-validation-regex
mode: search
patterns:
- pattern-either:
- pattern: |
validates ..., :format => <... $V ...>,...
- pattern: |
validates_format_of ..., :with => <... $V ...>,...
- metavariable-regex:
metavariable: $V
regex: /(.{2}(?<!\\A)[^\/]+|[^\/]+(?<!\\[Zz]))\/
message: $V Found an incorrectly-bounded regex passed to `validates_format_of` or
`validate ... format => ...`. Ruby regex behavior is multiline by default and
lines should be terminated by `\A` for beginning of line and `\Z` for end of line,
respectively.
languages:
- ruby
severity: ERROR
metadata:
source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_validation_regex.rb
category: security
cwe:
- 'CWE-185: Incorrect Regular Expression'
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
technology:
- ruby
- rails
references:
- https://brakemanscanner.org/docs/warning_types/format_validation/
- https://github.com/presidentbeef/brakeman/blob/aef6253a8b7bcb97116f2af1ed2a561a6ae35bd5/test/apps/rails3/app/models/account.rb
- https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/account.rb
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-validation-regex.check-validation-regex
shortlink: https://sg.run/ZPo7
semgrep.dev:
rule:
r_id: 20735
rv_id: 1263665
rule_id: OrUv1X
version_id: qkTR7DG
url: https://semgrep.dev/playground/r/qkTR7DG/ruby.rails.security.brakeman.check-validation-regex.check-validation-regex
origin: community
- id: go.lang.security.audit.net.fs-directory-listing.fs-directory-listing
message: 'Detected usage of ''http.FileServer'' as handler: this allows directory
listing and an attacker could navigate through directories looking for sensitive
files. Be sure to disable directory listing or restrict access to specific directories/files.'
severity: WARNING
languages:
- go
patterns:
- pattern-either:
- patterns:
- pattern-inside: |
$FS := http.FileServer(...)
...
- pattern-either:
- pattern: |
http.ListenAndServe(..., $FS)
- pattern: |
http.ListenAndServeTLS(..., $FS)
- pattern: |
http.Handle(..., $FS)
- pattern: |
http.HandleFunc(..., $FS)
- patterns:
- pattern: |
http.$FN(..., http.FileServer(...))
- metavariable-regex:
metavariable: $FN
regex: (ListenAndServe|ListenAndServeTLS|Handle|HandleFunc)
metadata:
category: security
cwe:
- 'CWE-548: Exposure of Information Through Directory Listing'
owasp:
- A06:2017 - Security Misconfiguration
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://github.com/OWASP/Go-SCP
- https://cwe.mitre.org/data/definitions/548.html
confidence: MEDIUM
technology:
- go
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing
shortlink: https://sg.run/4R8x
semgrep.dev:
rule:
r_id: 21300
rv_id: 1262944
rule_id: 5rU9JO
version_id: QkTGqX0
url: https://semgrep.dev/playground/r/QkTGqX0/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing
origin: community
- id: javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object
message: Detected DynamoDB query params that are tainted by `$EVENT` object. This
could lead to NoSQL injection if the variable is user-controlled and not properly
sanitized. Explicitly assign query params instead of passing data from `$EVENT`
directly to DynamoDB client.
metadata:
cwe:
- 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic'
owasp:
- A01:2017 - Injection
category: security
technology:
- javascript
- aws-lambda
- dynamodb
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
references:
- https://owasp.org/Top10/A03_2021-Injection
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object
shortlink: https://sg.run/X1e4
semgrep.dev:
rule:
r_id: 21320
rv_id: 945766
rule_id: 0oU1xk
version_id: GxTP7gN
url: https://semgrep.dev/playground/r/GxTP7gN/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern: $EVENT
- pattern-either:
- pattern-inside: |
exports.handler = function ($EVENT, ...) {
...
}
- pattern-inside: |
function $FUNC ($EVENT, ...) {...}
...
exports.handler = $FUNC
- pattern-inside: |
$FUNC = function ($EVENT, ...) {...}
...
exports.handler = $FUNC
pattern-sinks:
- patterns:
- focus-metavariable: $SINK
- pattern: |
$DC.$METHOD($SINK, ...)
- metavariable-regex:
metavariable: $METHOD
regex: (query|send|scan|delete|put|transactWrite|update|batchExecuteStatement|executeStatement|executeTransaction|transactWriteItems)
- pattern-either:
- pattern-inside: |
$DC = new $AWS.DocumentClient(...);
...
- pattern-inside: |
$DC = new $AWS.DynamoDB(...);
...
- pattern-inside: |
$DC = new DynamoDBClient(...);
...
- pattern-inside: |
$DC = DynamoDBDocumentClient.from(...);
...
pattern-sanitizers:
- patterns:
- pattern: |
{...}
- id: python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection
mode: taint
metadata:
cwe:
- 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic'
owasp:
- A01:2017 - Injection
category: security
technology:
- python
- boto3
- aws-lambda
- dynamodb
references:
- https://medium.com/appsecengineer/dynamodb-injection-1db99c2454ac
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection
shortlink: https://sg.run/jjrl
semgrep.dev:
rule:
r_id: 21321
rv_id: 946088
rule_id: KxUJ2B
version_id: 9lTy1rQ
url: https://semgrep.dev/playground/r/9lTy1rQ/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection
origin: community
message: Detected DynamoDB query filter that is tainted by `$EVENT` object. This
could lead to NoSQL injection if the variable is user-controlled and not properly
sanitized. Explicitly assign query params instead of passing data from `$EVENT`
directly to DynamoDB client.
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
pattern-sanitizers:
- patterns:
- pattern: |
{...}
pattern-sinks:
- patterns:
- focus-metavariable: $SINK
- pattern-either:
- pattern: $TABLE.scan(..., ScanFilter = $SINK, ...)
- pattern: $TABLE.query(..., QueryFilter = $SINK, ...)
- pattern-either:
- patterns:
- pattern-inside: |
$TABLE = $DB.Table(...)
...
- pattern-inside: |
$DB = boto3.resource('dynamodb', ...)
...
- pattern-inside: |
$TABLE = boto3.client('dynamodb', ...)
...
severity: ERROR
languages:
- python
- id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default
patterns:
- pattern: pyramid.authentication.$FUNC($...PARAMS)
- metavariable-pattern:
metavariable: $FUNC
pattern-either:
- pattern: AuthTktCookieHelper
- pattern: AuthTktAuthenticationPolicy
- pattern-not: pyramid.authentication.$FUNC(..., httponly=$HTTPONLY, ...)
- pattern-not: pyramid.authentication.$FUNC(..., **$PARAMS, ...)
- focus-metavariable: $...PARAMS
fix: |
$...PARAMS, httponly=True
message: Found a Pyramid Authentication Ticket cookie without the httponly option
correctly set. Pyramid cookies should be handled securely by setting httponly=True.
If this parameter is not properly set, your cookies are not properly protected
and are at risk of being stolen by an attacker.
metadata:
cwe:
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default
shortlink: https://sg.run/EprB
semgrep.dev:
rule:
r_id: 21437
rv_id: 1263557
rule_id: bwUXKB
version_id: RGT0L7K
url: https://semgrep.dev/playground/r/RGT0L7K/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default
origin: community
languages:
- python
severity: WARNING
- id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value
patterns:
- pattern-either:
- patterns:
- pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS)
- pattern: pyramid.authentication.AuthTktCookieHelper(..., httponly=$HTTPONLY,
...)
- patterns:
- pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS)
- pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., httponly=$HTTPONLY,
...)
- pattern: $HTTPONLY
- metavariable-pattern:
metavariable: $HTTPONLY
pattern: |
False
fix: |
True
message: Found a Pyramid Authentication Ticket cookie without the httponly option
correctly set. Pyramid cookies should be handled securely by setting httponly=True.
If this parameter is not properly set, your cookies are not properly protected
and are at risk of being stolen by an attacker.
metadata:
cwe:
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value
shortlink: https://sg.run/7DgQ
semgrep.dev:
rule:
r_id: 21438
rv_id: 1263558
rule_id: NbUq9e
version_id: A8Tgd8N
url: https://semgrep.dev/playground/r/A8Tgd8N/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value
origin: community
languages:
- python
severity: WARNING
- id: python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite
patterns:
- pattern-either:
- pattern: pyramid.authentication.AuthTktCookieHelper(..., samesite=$SAMESITE,
...)
- pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., samesite=$SAMESITE,
...)
- pattern: $SAMESITE
- metavariable-regex:
metavariable: $SAMESITE
regex: (?!'Lax')
fix: |
'Lax'
message: Found a Pyramid Authentication Ticket without the samesite option correctly
set. Pyramid cookies should be handled securely by setting samesite='Lax'. If
this parameter is not properly set, your cookies are not properly protected and
are at risk of being stolen by an attacker.
metadata:
cwe:
- 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite
shortlink: https://sg.run/LYrY
semgrep.dev:
rule:
r_id: 21439
rv_id: 1263559
rule_id: kxUYjY
version_id: BjTkZ51
url: https://semgrep.dev/playground/r/BjTkZ51/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite
origin: community
languages:
- python
severity: WARNING
- id: python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default
patterns:
- pattern-either:
- patterns:
- pattern-not: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE,
...)
- pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS)
- pattern: pyramid.authentication.AuthTktCookieHelper(...)
- patterns:
- pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE,
...)
- pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS)
- pattern: pyramid.authentication.AuthTktAuthenticationPolicy(...)
fix-regex:
regex: (.*)\)
replacement: \1, secure=True)
message: Found a Pyramid Authentication Ticket cookie using an unsafe default for
the secure option. Pyramid cookies should be handled securely by setting secure=True.
If this parameter is not properly set, your cookies are not properly protected
and are at risk of being stolen by an attacker.
metadata:
cwe:
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default
shortlink: https://sg.run/8WxQ
semgrep.dev:
rule:
r_id: 21440
rv_id: 1263560
rule_id: wdUKzn
version_id: DkTRbJn
url: https://semgrep.dev/playground/r/DkTRbJn/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default
origin: community
languages:
- python
severity: WARNING
- id: python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value
patterns:
- pattern-either:
- patterns:
- pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS)
- pattern: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE, ...)
- patterns:
- pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS)
- pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE,
...)
- pattern: $SECURE
- metavariable-pattern:
metavariable: $SECURE
pattern: |
False
fix: |
True
message: Found a Pyramid Authentication Ticket cookie without the secure option
correctly set. Pyramid cookies should be handled securely by setting secure=True.
If this parameter is not properly set, your cookies are not properly protected
and are at risk of being stolen by an attacker.
metadata:
cwe:
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value
shortlink: https://sg.run/gjp5
semgrep.dev:
rule:
r_id: 21441
rv_id: 1263561
rule_id: x8UqAp
version_id: WrTqK93
url: https://semgrep.dev/playground/r/WrTqK93/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value
origin: community
languages:
- python
severity: WARNING
- id: python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally
patterns:
- pattern-inside: |
$CONFIG.set_default_csrf_options(..., check_origin=$CHECK_ORIGIN, ...)
- pattern: $CHECK_ORIGIN
- metavariable-comparison:
metavariable: $CHECK_ORIGIN
comparison: $CHECK_ORIGIN == False
message: Automatic check of the referrer for cross-site request forgery tokens has
been explicitly disabled globally, which might leave views unprotected when an
unsafe CSRF storage policy is used. Use 'pyramid.config.Configurator.set_default_csrf_options(check_origin=True)'
to turn the automatic check for all unsafe methods (per RFC2616).
languages:
- python
severity: ERROR
fix: |
True
metadata:
cwe:
- 'CWE-352: Cross-Site Request Forgery (CSRF)'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site Request Forgery (CSRF)
source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally
shortlink: https://sg.run/3GeW
semgrep.dev:
rule:
r_id: 21443
rv_id: 1263563
rule_id: eqU9Le
version_id: K3TKkeo
url: https://semgrep.dev/playground/r/K3TKkeo/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally
origin: community
- id: python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled
message: Origin check for the CSRF token is disabled for this view. This might represent
a security risk if the CSRF storage policy is not known to be secure.
metadata:
cwe:
- 'CWE-352: Cross-Site Request Forgery (CSRF)'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
asvs:
section: V4 Access Control
control_id: 4.2.2 CSRF
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V4-Access-Control.md#v42-operation-level-access-control
version: '4'
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site Request Forgery (CSRF)
source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled
shortlink: https://sg.run/4RB9
semgrep.dev:
rule:
r_id: 21444
rv_id: 1263564
rule_id: v8UGpL
version_id: qkTR7Gv
url: https://semgrep.dev/playground/r/qkTR7Gv/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled
origin: community
severity: WARNING
languages:
- python
patterns:
- pattern-inside: |
from pyramid.view import view_config
...
@view_config(..., check_origin=$CHECK_ORIGIN, ...)
def $VIEW(...):
...
- pattern: $CHECK_ORIGIN
- metavariable-comparison:
metavariable: $CHECK_ORIGIN
comparison: $CHECK_ORIGIN == False
fix: |
True
- id: python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default
patterns:
- pattern-either:
- pattern-inside: |
@pyramid.view.view_config(...)
def $VIEW($REQUEST):
...
$RESPONSE = $REQUEST.response
...
- pattern-inside: |
def $VIEW(...):
...
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
...
- pattern-not: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...)
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
- pattern: $RESPONSE.set_cookie(...)
fix-regex:
regex: (.*)\)
replacement: \1, httponly=True)
message: Found a Pyramid cookie using an unsafe default for the httponly option.
Pyramid cookies should be handled securely by setting httponly=True in response.set_cookie(...).
If this parameter is not properly set, your cookies are not properly protected
and are at risk of being stolen by an attacker.
metadata:
cwe:
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default
shortlink: https://sg.run/P19v
semgrep.dev:
rule:
r_id: 21445
rv_id: 1263565
rule_id: d8UPQ7
version_id: l4TJRbo
url: https://semgrep.dev/playground/r/l4TJRbo/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default
origin: community
languages:
- python
severity: WARNING
- id: python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value
patterns:
- pattern-either:
- pattern-inside: |
@pyramid.view.view_config(...)
def $VIEW($REQUEST):
...
$RESPONSE = $REQUEST.response
...
- pattern-inside: |
def $VIEW(...):
...
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
...
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
- pattern: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...)
- pattern: $HTTPONLY
- metavariable-pattern:
metavariable: $HTTPONLY
pattern: |
False
fix: |
True
message: Found a Pyramid cookie without the httponly option correctly set. Pyramid
cookies should be handled securely by setting httponly=True in response.set_cookie(...).
If this parameter is not properly set, your cookies are not properly protected
and are at risk of being stolen by an attacker.
metadata:
cwe:
- 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://owasp.org/www-community/controls/SecureCookieAttribute
- https://owasp.org/www-community/HttpOnly
- https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html#httponly-attribute
category: security
technology:
- pyramid
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value
shortlink: https://sg.run/JbqP
semgrep.dev:
rule:
r_id: 21446
rv_id: 1263566
rule_id: ZqU37W
version_id: YDTZe54
url: https://semgrep.dev/playground/r/YDTZe54/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value
origin: community
languages:
- python
severity: WARNING
- id: python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default
patterns:
- pattern-either:
- pattern-inside: |
@pyramid.view.view_config(...)
def $VIEW($REQUEST):
...
$RESPONSE = $REQUEST.response
...
- pattern-inside: |
def $VIEW(...):
...
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
...
- pattern-not: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...)
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
- pattern: $RESPONSE.set_cookie(...)
fix-regex:
regex: (.*)\)
replacement: \1, samesite='Lax')
message: Found a Pyramid cookie using an unsafe value for the samesite option. Pyramid
cookies should be handled securely by setting samesite='Lax' in response.set_cookie(...).
If this parameter is not properly set, your cookies are not properly protected
and are at risk of being stolen by an attacker.
metadata:
cwe:
- 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default
shortlink: https://sg.run/5AWj
semgrep.dev:
rule:
r_id: 21447
rv_id: 1263567
rule_id: nJUp80
version_id: 6xT293z
url: https://semgrep.dev/playground/r/6xT293z/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default
origin: community
languages:
- python
severity: WARNING
- id: python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value
patterns:
- pattern-either:
- pattern-inside: |
@pyramid.view.view_config(...)
def $VIEW($REQUEST):
...
$RESPONSE = $REQUEST.response
...
- pattern-inside: |
def $VIEW(...):
...
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
...
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
- pattern: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...)
- pattern: $SAMESITE
- metavariable-regex:
metavariable: $SAMESITE
regex: (?!'Lax')
fix: |
'Lax'
message: Found a Pyramid cookie without the samesite option correctly set. Pyramid
cookies should be handled securely by setting samesite='Lax' in response.set_cookie(...).
If this parameter is not properly set, your cookies are not properly protected
and are at risk of being stolen by an attacker.
metadata:
cwe:
- 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value
shortlink: https://sg.run/GXR6
semgrep.dev:
rule:
r_id: 21448
rv_id: 1263568
rule_id: EwUgpY
version_id: o5TbDv5
url: https://semgrep.dev/playground/r/o5TbDv5/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value
origin: community
languages:
- python
severity: WARNING
- id: python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default
patterns:
- pattern-either:
- pattern-inside: |
@pyramid.view.view_config(...)
def $VIEW($REQUEST):
...
$RESPONSE = $REQUEST.response
...
- pattern-inside: |
def $VIEW(...):
...
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
...
- pattern-not: $RESPONSE.set_cookie(..., secure=$SECURE, ...)
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
- pattern: $RESPONSE.set_cookie(...)
fix-regex:
regex: (.*)\)
replacement: \1, secure=True)
message: Found a Pyramid cookie using an unsafe default for the secure option. Pyramid
cookies should be handled securely by setting secure=True in response.set_cookie(...).
If this parameter is not properly set, your cookies are not properly protected
and are at risk of being stolen by an attacker.
metadata:
cwe:
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default
shortlink: https://sg.run/RbrN
semgrep.dev:
rule:
r_id: 21449
rv_id: 1263569
rule_id: 7KUr15
version_id: zyTb2dX
url: https://semgrep.dev/playground/r/zyTb2dX/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default
origin: community
languages:
- python
severity: WARNING
- id: python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value
patterns:
- pattern-either:
- pattern-inside: |
@pyramid.view.view_config(...)
def $VIEW($REQUEST):
...
$RESPONSE = $REQUEST.response
...
- pattern-inside: |
def $VIEW(...):
...
$RESPONSE = pyramid.httpexceptions.HTTPFound(...)
...
- pattern-not: $RESPONSE.set_cookie(..., **$PARAMS)
- pattern: $RESPONSE.set_cookie(..., secure=$SECURE, ...)
- pattern: $SECURE
- metavariable-pattern:
metavariable: $SECURE
pattern: |
False
fix: |
True
message: Found a Pyramid cookie without the secure option correctly set. Pyramid
cookies should be handled securely by setting secure=True in response.set_cookie(...).
If this parameter is not properly set, your cookies are not properly protected
and are at risk of being stolen by an attacker.
metadata:
cwe:
- 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value
shortlink: https://sg.run/AzjB
semgrep.dev:
rule:
r_id: 21450
rv_id: 1263570
rule_id: L1UX2J
version_id: pZT03oJ
url: https://semgrep.dev/playground/r/pZT03oJ/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value
origin: community
languages:
- python
severity: WARNING
- id: python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally
patterns:
- pattern-inside: |
$CONFIG.set_default_csrf_options(..., require_csrf=$REQUIRE_CSRF, ...)
- pattern: $REQUIRE_CSRF
- metavariable-comparison:
metavariable: $REQUIRE_CSRF
comparison: $REQUIRE_CSRF == False
message: Automatic check of cross-site request forgery tokens has been explicitly
disabled globally, which might leave views unprotected. Use 'pyramid.config.Configurator.set_default_csrf_options(require_csrf=True)'
to turn the automatic check for all unsafe methods (per RFC2616).
languages:
- python
severity: ERROR
fix: |
True
metadata:
cwe:
- 'CWE-352: Cross-Site Request Forgery (CSRF)'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site Request Forgery (CSRF)
source: https://semgrep.dev/r/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally
shortlink: https://sg.run/Bx2R
semgrep.dev:
rule:
r_id: 21451
rv_id: 1263571
rule_id: 8GUKqP
version_id: 2KTv2en
url: https://semgrep.dev/playground/r/2KTv2en/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally
origin: community
- id: python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response
message: Detected data rendered directly to the end user via 'Response'. This bypasses
Pyramid's built-in cross-site scripting (XSS) defenses and could result in an
XSS vulnerability. Use Pyramid's template engines to safely render HTML.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- pyramid
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response
shortlink: https://sg.run/DX8G
semgrep.dev:
rule:
r_id: 21452
rv_id: 1263572
rule_id: gxUeA8
version_id: X0TzyEe
url: https://semgrep.dev/playground/r/X0TzyEe/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response
origin: community
languages:
- python
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-inside: |
@pyramid.view.view_config( ... )
def $VIEW($REQ):
...
- pattern: $REQ.$ANYTHING
- pattern-not: $REQ.dbsession
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
pyramid.request.Response.text($SINK)
- pattern: |
pyramid.request.Response($SINK)
- pattern: |
$REQ.response.body = $SINK
- pattern: |
$REQ.response.text = $SINK
- pattern: |
$REQ.response.ubody = $SINK
- pattern: |
$REQ.response.unicode_body = $SINK
- pattern: $SINK
- id: python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection
message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause
sql injections if the developer inputs raw SQL into the before-mentioned clauses.
This pattern captures relevant cases in which the developer inputs raw SQL into
the distinct, having, group_by, order_by or filter clauses and injects user-input
into the raw SQL with any function besides "bindparams". Use bindParams to securely
bind user-input to SQL statements.
languages:
- python
severity: ERROR
metadata:
category: security
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://docs.sqlalchemy.org/en/14/tutorial/data_select.html#tutorial-selecting-data
technology:
- pyramid
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection
shortlink: https://sg.run/W7eE
semgrep.dev:
rule:
r_id: 21453
rv_id: 1263573
rule_id: QrUZ7l
version_id: jQTn5WA
url: https://semgrep.dev/playground/r/jQTn5WA/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-inside: |
from pyramid.view import view_config
...
@view_config( ... )
def $VIEW($REQ):
...
- pattern: $REQ.$ANYTHING
- pattern-not: $REQ.dbsession
pattern-sinks:
- patterns:
- pattern-inside: |
$QUERY = $REQ.dbsession.query(...)
...
- pattern-either:
- pattern: |
$QUERY.$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...))
- pattern: |
$QUERY.join(...).$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...))
- pattern: $SINK
- metavariable-regex:
metavariable: $SQLFUNC
regex: (group_by|order_by|distinct|having|filter)
- metavariable-regex:
metavariable: $FORMATFUNC
regex: (?!bindparams)
fix-regex:
regex: format
replacement: bindparams
- id: javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint
message: Use of angular.element can lead to XSS if user-input is treated as part
of the HTML element within `$SINK`. It is recommended to contextually output encode
user-input, before inserting into `$SINK`. If the HTML needs to be preserved it
is recommended to sanitize the input using $sce.getTrustedHTML or $sanitize.
metadata:
confidence: MEDIUM
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
references:
- https://docs.angularjs.org/api/ng/function/angular.element
- https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf
category: security
technology:
- angularjs
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint
shortlink: https://sg.run/5AQ0
semgrep.dev:
rule:
r_id: 21503
rv_id: 1263091
rule_id: GdUP71
version_id: 44TEj8L
url: https://semgrep.dev/playground/r/44TEj8L/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: window.location.search
- pattern: window.document.location.search
- pattern: document.location.search
- pattern: location.search
- pattern: $location.search(...)
- patterns:
- pattern-either:
- pattern: $DECODE(<... location.hash ...>)
- pattern: $DECODE(<... window.location.hash ...>)
- pattern: $DECODE(<... document.location.hash ...>)
- pattern: $DECODE(<... location.href ...>)
- pattern: $DECODE(<... window.location.href ...>)
- pattern: $DECODE(<... document.location.href ...>)
- pattern: $DECODE(<... document.URL ...>)
- pattern: $DECODE(<... window.document.URL ...>)
- pattern: $DECODE(<... document.location.href ...>)
- pattern: $DECODE(<... document.location.href ...>)
- pattern: $DECODE(<... $location.absUrl() ...>)
- pattern: $DECODE(<... $location.url() ...>)
- pattern: $DECODE(<... $location.hash() ...>)
- metavariable-regex:
metavariable: $DECODE
regex: ^(unescape|decodeURI|decodeURIComponent)$
- patterns:
- pattern-inside: $http.$METHOD(...).$CONTINUE(function $FUNC($RES) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|delete|head|jsonp|post|put|patch)
- pattern: $RES.data
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
angular.element(...). ... .$SINK($QUERY)
- pattern-inside: |
$ANGULAR = angular.element(...)
...
$ANGULAR. ... .$SINK($QUERY)
- metavariable-regex:
metavariable: $SINK
regex: ^(after|append|html|prepend|replaceWith|wrap)$
- focus-metavariable: $QUERY
pattern-sanitizers:
- patterns:
- pattern-either:
- pattern: $sce.getTrustedHtml(...)
- pattern: $sanitize(...)
- pattern: DOMPurify.sanitize(...)
- id: python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization
mode: taint
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context):
...
pattern-sinks:
- patterns:
- focus-metavariable: $SINK
- pattern-either:
- pattern: pickle.load($SINK,...)
- pattern: pickle.loads($SINK,...)
- pattern: _pickle.load($SINK,...)
- pattern: _pickle.loads($SINK,...)
- pattern: cPickle.load($SINK,...)
- pattern: cPickle.loads($SINK,...)
- pattern: dill.load($SINK,...)
- pattern: dill.loads($SINK,...)
- pattern: shelve.open($SINK,...)
message: Avoid using `pickle`, which is known to lead to code execution vulnerabilities.
When unpickling, the serialized data could be manipulated to run arbitrary code.
Instead, consider serializing the relevant data as JSON or a similar text-based
serialization format.
metadata:
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
references:
- https://docs.python.org/3/library/pickle.html
- https://davidhamann.de/2020/04/05/exploiting-python-pickle/
category: security
technology:
- python
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization
shortlink: https://sg.run/JbjW
semgrep.dev:
rule:
r_id: 21602
rv_id: 1263345
rule_id: JDUDQg
version_id: LjTkgd9
url: https://semgrep.dev/playground/r/LjTkgd9/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization
origin: community
languages:
- python
severity: WARNING
- id: php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection
mode: taint
pattern-sources:
- patterns:
- focus-metavariable: $ARG
- pattern-inside: |
Route::$METHOD($ROUTE_NAME, function(...,$ARG,...){...})
pattern-sanitizers:
- patterns:
- pattern: |
DB::raw("...",[...])
pattern-sinks:
- patterns:
- pattern: |
DB::raw(...)
message: HTTP method [$METHOD] to Laravel route $ROUTE_NAME is vulnerable to SQL
injection via string concatenation or unsafe interpolation.
languages:
- php
severity: WARNING
metadata:
category: security
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Laravel_Cheat_Sheet.md
technology:
- php
- laravel
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection
shortlink: https://sg.run/x94g
semgrep.dev:
rule:
r_id: 21674
rv_id: 1263305
rule_id: zdUln0
version_id: qkTR7A9
url: https://semgrep.dev/playground/r/qkTR7A9/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection
origin: community
- id: php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator
mode: taint
pattern-sources:
- patterns:
- pattern: |
public function $F(...,Request $R,...){...}
- focus-metavariable: $R
- patterns:
- pattern-either:
- pattern: |
$this->$PROPERTY
- pattern: |
$this->$PROPERTY->$GET
- metavariable-pattern:
metavariable: $PROPERTY
patterns:
- pattern-either:
- pattern: query
- pattern: request
- pattern: headers
- pattern: cookies
- pattern: cookie
- pattern: files
- pattern: file
- pattern: allFiles
- pattern: input
- pattern: all
- pattern: post
- pattern: json
- pattern-either:
- pattern-inside: |
class $CL extends Illuminate\Http\Request {...}
- pattern-inside: |
class $CL extends Illuminate\Foundation\Http\FormRequest {...}
pattern-sinks:
- patterns:
- pattern: |
Illuminate\Validation\Rule::unique(...)->ignore(...,$IGNORE,...)
- focus-metavariable: $IGNORE
message: Found a request argument passed to an `ignore()` definition in a Rule constraint.
This can lead to SQL injection.
languages:
- php
severity: ERROR
metadata:
category: security
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
technology:
- php
- laravel
references:
- https://laravel.com/docs/9.x/validation#rule-unique
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator
shortlink: https://sg.run/vkeb
semgrep.dev:
rule:
r_id: 21677
rv_id: 1263314
rule_id: X5ULgE
version_id: DkTRbBl
url: https://semgrep.dev/playground/r/DkTRbBl/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator
origin: community
- id: java.spring.security.injection.tainted-file-path.tainted-file-path
languages:
- java
severity: ERROR
message: Detected user input controlling a file path. An attacker could control
the location of this file, to include going backwards in the directory with '../'.
To address this, ensure that user-controlled variables in file paths are sanitized.
You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...)
to only retrieve the file name from the path.
options:
interfile: true
metadata:
cwe:
- 'CWE-23: Relative Path Traversal'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://owasp.org/www-community/attacks/Path_Traversal
category: security
technology:
- java
- spring
subcategory:
- vuln
impact: HIGH
likelihood: MEDIUM
confidence: HIGH
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/java.spring.security.injection.tainted-file-path.tainted-file-path
shortlink: https://sg.run/x9o0
semgrep.dev:
rule:
r_id: 22074
rv_id: 1263084
rule_id: lBUxok
version_id: ExTEx6Y
url: https://semgrep.dev/playground/r/ExTEx6Y/java.spring.security.injection.tainted-file-path.tainted-file-path
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
...
}
- pattern-inside: |
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
...
}
- metavariable-regex:
metavariable: $TYPE
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
- metavariable-regex:
metavariable: $REQ
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute)
- focus-metavariable: $SOURCE
pattern-sinks:
- patterns:
- pattern-either:
- pattern: new File(...)
- pattern: new java.io.File(...)
- pattern: new FileReader(...)
- pattern: new java.io.FileReader(...)
- pattern: new FileInputStream(...)
- pattern: new java.io.FileInputStream(...)
- pattern: (Paths $PATHS).get(...)
- patterns:
- pattern: |
$CLASS.$FUNC(...)
- metavariable-regex:
metavariable: $FUNC
regex: ^(getResourceAsStream|getResource)$
- patterns:
- pattern-either:
- pattern: new ClassPathResource($FILE, ...)
- pattern: ResourceUtils.getFile($FILE, ...)
- pattern: new FileOutputStream($FILE, ...)
- pattern: new java.io.FileOutputStream($FILE, ...)
- pattern: new StreamSource($FILE, ...)
- pattern: new javax.xml.transform.StreamSource($FILE, ...)
- pattern: FileUtils.openOutputStream($FILE, ...)
- focus-metavariable: $FILE
pattern-sanitizers:
- pattern: org.apache.commons.io.FilenameUtils.getName(...)
- id: java.spring.security.injection.tainted-html-string.tainted-html-string
languages:
- java
severity: ERROR
message: Detected user input flowing into a manually constructed HTML string. You
may be accidentally bypassing secure methods of rendering HTML by manually constructing
HTML and this could create a cross-site scripting vulnerability, which could let
attackers steal sensitive user data. To be sure this is safe, check that the HTML
is rendered safely. You can use the OWASP ESAPI encoder if you must render user
data.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
category: security
technology:
- java
- spring
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/java.spring.security.injection.tainted-html-string.tainted-html-string
shortlink: https://sg.run/ObdR
semgrep.dev:
rule:
r_id: 22075
rv_id: 1409395
rule_id: YGUvkL
version_id: 3ZT2598
url: https://semgrep.dev/playground/r/3ZT2598/java.spring.security.injection.tainted-html-string.tainted-html-string
origin: community
mode: taint
pattern-sources:
- label: INPUT
patterns:
- pattern-either:
- pattern-inside: |
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
...
}
- pattern-inside: |
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
...
}
- metavariable-regex:
metavariable: $TYPE
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
- metavariable-regex:
metavariable: $REQ
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute)
- focus-metavariable: $SOURCE
- label: CONCAT
by-side-effect: true
requires: INPUT
patterns:
- pattern-either:
- pattern: |
"$HTMLSTR" + ...
- pattern: |
"$HTMLSTR".concat(...)
- patterns:
- pattern-inside: |
StringBuilder $SB = new StringBuilder("$HTMLSTR");
...
- pattern: $SB.append(...)
- patterns:
- pattern-inside: |
$VAR = "$HTMLSTR";
...
- pattern: $VAR += ...
- pattern: String.format("$HTMLSTR", ...)
- patterns:
- pattern-inside: |
String $VAR = "$HTMLSTR";
...
- pattern: String.format($VAR, ...)
- metavariable-regex:
metavariable: $HTMLSTR
regex: ^<\w+
pattern-propagators:
- pattern: (StringBuilder $SB).append($...TAINTED)
from: $...TAINTED
to: $SB
- pattern: $VAR += $...TAINTED
from: $...TAINTED
to: $VAR
pattern-sinks:
- requires: CONCAT
patterns:
- pattern-either:
- pattern: new ResponseEntity<>($PAYLOAD, ...)
- pattern: new ResponseEntity<$ERROR>($PAYLOAD, ...)
- pattern: ResponseEntity. ... .body($PAYLOAD)
- patterns:
- pattern: |
ResponseEntity.$RESPFUNC($PAYLOAD). ...
- metavariable-regex:
metavariable: $RESPFUNC
regex: ^(ok|of)$
- focus-metavariable: $PAYLOAD
pattern-sanitizers:
- pattern-either:
- pattern: Encode.forHtml(...)
- pattern: (PolicyFactory $POLICY).sanitize(...)
- pattern: (AntiSamy $AS).scan(...)
- pattern: JSoup.clean(...)
- id: java.spring.security.injection.tainted-system-command.tainted-system-command
languages:
- java
severity: ERROR
mode: taint
pattern-propagators:
- pattern: (StringBuilder $STRB).append($INPUT)
from: $INPUT
to: $STRB
label: CONCAT
requires: INPUT
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
...
}
- pattern-inside: |
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
...
}
- metavariable-regex:
metavariable: $TYPE
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
- metavariable-regex:
metavariable: $REQ
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute)
- focus-metavariable: $SOURCE
label: INPUT
- patterns:
- pattern-either:
- pattern: $X + $SOURCE
- pattern: $SOURCE + $Y
- pattern: String.format("...", ..., $SOURCE, ...)
- pattern: String.join("...", ..., $SOURCE, ...)
- pattern: (String $STR).concat($SOURCE)
- pattern: $SOURCE.concat(...)
- pattern: $X += $SOURCE
- pattern: $SOURCE += $X
label: CONCAT
requires: INPUT
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
(Process $P) = new Process(...);
- pattern: |
(ProcessBuilder $PB).command(...);
- patterns:
- pattern-either:
- pattern: |
(Runtime $R).$EXEC(...);
- pattern: |
Runtime.getRuntime(...).$EXEC(...);
- metavariable-regex:
metavariable: $EXEC
regex: (exec|loadLibrary|load)
- patterns:
- pattern: |
(ProcessBuilder $PB).command(...).$ADD(...);
- metavariable-regex:
metavariable: $ADD
regex: (add|addAll)
- patterns:
- pattern-either:
- patterns:
- pattern-inside: |
$BUILDER = new ProcessBuilder(...);
...
- pattern: $BUILDER.start(...)
- pattern: |
new ProcessBuilder(...). ... .start(...);
requires: CONCAT
message: 'Detected user input entering a method which executes a system command.
This could result in a command injection vulnerability, which allows an attacker
to inject an arbitrary system command onto the server. The attacker could download
malware onto or steal data from the server. Instead, use ProcessBuilder, separating
the command into individual arguments, like this: `new ProcessBuilder("ls", "-al",
targetDirectory)`. Further, make sure you hardcode or allowlist the actual command
so that attackers can''t run arbitrary commands.'
metadata:
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- java
- spring
confidence: HIGH
references:
- https://www.stackhawk.com/blog/command-injection-java/
- https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html
- https://github.com/github/codeql/blob/main/java/ql/src/Security/CWE/CWE-078/ExecUnescaped.java
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/java.spring.security.injection.tainted-system-command.tainted-system-command
shortlink: https://sg.run/epY0
semgrep.dev:
rule:
r_id: 22076
rv_id: 1263087
rule_id: 6JUxGN
version_id: 8KT5rnP
url: https://semgrep.dev/playground/r/8KT5rnP/java.spring.security.injection.tainted-system-command.tainted-system-command
origin: community
- id: java.spring.security.injection.tainted-url-host.tainted-url-host
languages:
- java
severity: ERROR
message: User data flows into the host portion of this manually-constructed URL.
This could allow an attacker to send data to their own server, potentially exposing
sensitive data such as cookies or authorization information sent with this request.
They could also probe internal servers or other resources that the server running
this code can access. (This is called server-side request forgery, or SSRF.) Do
not allow arbitrary hosts. Instead, create an allowlist for approved hosts, hardcode
the correct host, or ensure that the user data can only affect the path or parameters.
options:
interfile: true
metadata:
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
category: security
technology:
- java
- spring
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/java.spring.security.injection.tainted-url-host.tainted-url-host
shortlink: https://sg.run/vkYn
semgrep.dev:
rule:
r_id: 22077
rv_id: 1263088
rule_id: oqUZo8
version_id: gETB708
url: https://semgrep.dev/playground/r/gETB708/java.spring.security.injection.tainted-url-host.tainted-url-host
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
...
}
- pattern-inside: |
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
...
}
- metavariable-regex:
metavariable: $TYPE
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
- metavariable-regex:
metavariable: $REQ
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute)
- focus-metavariable: $SOURCE
pattern-sinks:
- pattern-either:
- pattern: new URL($ONEARG)
- patterns:
- pattern-either:
- pattern: |
"$URLSTR" + ...
- pattern: |
"$URLSTR".concat(...)
- patterns:
- pattern-inside: |
StringBuilder $SB = new StringBuilder("$URLSTR");
...
- pattern: $SB.append(...)
- patterns:
- pattern-inside: |
$VAR = "$URLSTR";
...
- pattern: $VAR += ...
- patterns:
- pattern: String.format("$URLSTR", ...)
- pattern-not: String.format("$URLSTR", "...", ...)
- patterns:
- pattern-inside: |
String $VAR = "$URLSTR";
...
- pattern: String.format($VAR, ...)
- metavariable-regex:
metavariable: $URLSTR
regex: http(s?)://%(v|s|q).*
- id: ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization
mode: taint
languages:
- ruby
message: Deserialization of a string tainted by `event` object found. Objects in
Ruby can be serialized into strings, then later loaded from strings. However,
uses of `load` can cause remote code execution. Loading user input with MARSHAL,
YAML or CSV can potentially be dangerous. If you need to deserialize untrusted
data, you should use JSON as it is only capable of returning 'primitive' types
such as strings, arrays, hashes, numbers and nil.
metadata:
references:
- https://ruby-doc.org/core-3.1.2/doc/security_rdoc.html
- https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ
- https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb
category: security
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
technology:
- ruby
- aws-lambda
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization
shortlink: https://sg.run/dplX
semgrep.dev:
rule:
r_id: 22078
rv_id: 1263585
rule_id: zdUlNJ
version_id: vdT06gR
url: https://semgrep.dev/playground/r/vdT06gR/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization
origin: community
pattern-sinks:
- patterns:
- pattern: $SINK
- pattern-either:
- pattern-inside: |
YAML.load($SINK,...)
- pattern-inside: |
CSV.load($SINK,...)
- pattern-inside: |
Marshal.load($SINK,...)
- pattern-inside: |
Marshal.restore($SINK,...)
pattern-sources:
- patterns:
- pattern: event
- pattern-inside: |
def $HANDLER(event, context)
...
end
severity: WARNING
- id: javascript.express.security.audit.express-libxml-noent.express-libxml-noent
message: The libxml library processes user-input with the `noent` attribute is set
to `true` which can lead to being vulnerable to XML External Entities (XXE) type
attacks. It is recommended to set `noent` to `false` when using this feature to
ensure you are protected.
options:
interfile: true
metadata:
interfile: true
references:
- https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
technology:
- express
category: security
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-noent.express-libxml-noent
shortlink: https://sg.run/Z75x
semgrep.dev:
rule:
r_id: 22079
rv_id: 1263138
rule_id: pKUNeD
version_id: d6TyxpX
url: https://semgrep.dev/playground/r/d6TyxpX/javascript.express.security.audit.express-libxml-noent.express-libxml-noent
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
- pattern: files.$ANYTHING.data.toString('utf8')
- pattern: files.$ANYTHING['data'].toString('utf8')
pattern-sinks:
- pattern-either:
- patterns:
- pattern-either:
- pattern-inside: |
$XML = require('$IMPORT')
...
- pattern-inside: |
import $XML from '$IMPORT'
...
- pattern-inside: |
import * as $XML from '$IMPORT'
...
- metavariable-regex:
metavariable: $IMPORT
regex: ^(libxmljs|libxmljs2)$
- pattern-inside: $XML.$FUNC($QUERY, {...,noent:true,...})
- metavariable-regex:
metavariable: $FUNC
regex: ^(parseXmlString|parseXml)$
- focus-metavariable: $QUERY
- id: javascript.express.security.audit.express-open-redirect.express-open-redirect
message: The application redirects to a URL specified by user-supplied input `$REQ`
that is not validated. This could redirect users to malicious locations. Consider
using an allow-list approach to validate URLs, or warn users they are being redirected
to a third-party website.
metadata:
technology:
- express
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html
cwe:
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
category: security
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Open Redirect
source: https://semgrep.dev/r/javascript.express.security.audit.express-open-redirect.express-open-redirect
shortlink: https://sg.run/EpoP
semgrep.dev:
rule:
r_id: 22081
rv_id: 1263140
rule_id: X5ULkq
version_id: nWT2L0v
url: https://semgrep.dev/playground/r/nWT2L0v/javascript.express.security.audit.express-open-redirect.express-open-redirect
origin: community
languages:
- javascript
- typescript
severity: WARNING
options:
taint_unify_mvars: true
symbolic_propagation: true
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-either:
- pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE)
- pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE + $...A)
- pattern: $RES.redirect(`$HTTP${$REQ. ... .$VALUE}...`)
- pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...])
- pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...] + $...A)
- pattern: $RES.redirect(`$HTTP${$REQ.$VALUE[...]}...`)
- metavariable-regex:
metavariable: $HTTP
regex: ^https?:\/\/$
- pattern-either:
- pattern: $REQ. ... .$VALUE
- patterns:
- pattern-either:
- pattern: $RES.redirect($REQ. ... .$VALUE)
- pattern: $RES.redirect($REQ. ... .$VALUE + $...A)
- pattern: $RES.redirect(`${$REQ. ... .$VALUE}...`)
- pattern: $REQ. ... .$VALUE
- patterns:
- pattern-either:
- pattern: $RES.redirect($REQ.$VALUE['...'])
- pattern: $RES.redirect($REQ.$VALUE['...'] + $...A)
- pattern: $RES.redirect(`${$REQ.$VALUE['...']}...`)
- pattern: $REQ.$VALUE
- patterns:
- pattern-either:
- pattern-inside: |
$ASSIGN = $REQ. ... .$VALUE
...
- pattern-inside: |
$ASSIGN = $REQ.$VALUE['...']
...
- pattern-inside: |
$ASSIGN = $REQ. ... .$VALUE + $...A
...
- pattern-inside: "$ASSIGN = $REQ.$VALUE['...'] + $...A\n... \n"
- pattern-inside: |
$ASSIGN = `${$REQ. ... .$VALUE}...`
...
- pattern-inside: "$ASSIGN = `${$REQ.$VALUE['...']}...`\n... \n"
- pattern-either:
- pattern: $RES.redirect($ASSIGN)
- pattern: $RES.redirect($ASSIGN + $...FOO)
- pattern: $RES.redirect(`${$ASSIGN}...`)
- focus-metavariable: $ASSIGN
- id: javascript.express.security.audit.express-res-sendfile.express-res-sendfile
message: The application processes user-input, this is passed to res.sendFile which
can allow an attacker to arbitrarily read files on the system through path traversal.
It is recommended to perform input validation in addition to canonicalizing the
path. This allows you to validate the path against the intended directory it should
be accessing.
metadata:
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html
technology:
- express
category: security
cwe:
- 'CWE-73: External Control of File Name or Path'
owasp:
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Path Traversal
source: https://semgrep.dev/r/javascript.express.security.audit.express-res-sendfile.express-res-sendfile
shortlink: https://sg.run/7DJk
semgrep.dev:
rule:
r_id: 22082
rv_id: 1263142
rule_id: j2UzDx
version_id: 7ZTE3X9
url: https://semgrep.dev/playground/r/7ZTE3X9/javascript.express.security.audit.express-res-sendfile.express-res-sendfile
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern-inside: |
function ... (...,$REQ: $TYPE, ...) {...}
- metavariable-regex:
metavariable: $TYPE
regex: ^(string|String)
pattern-sinks:
- patterns:
- pattern-either:
- pattern: $RES.$METH($QUERY,...)
- pattern-not-inside: $RES.$METH($QUERY,$OPTIONS)
- metavariable-regex:
metavariable: $METH
regex: ^(sendfile|sendFile)$
- focus-metavariable: $QUERY
- id: javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret
message: A hard-coded credential was detected. It is not recommended to store credentials
in source-code, as this risks secrets being leaked and used by either an internal
or external malicious adversary. It is recommended to use environment variables
to securely provide credentials or retrieve credentials from a secure vault or
HSM (Hardware Security Module).
options:
interfile: true
metadata:
interfile: true
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
category: security
technology:
- express
- secrets
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Hard-coded Secrets
source: https://semgrep.dev/r/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret
shortlink: https://sg.run/LYvG
semgrep.dev:
rule:
r_id: 22083
rv_id: 1263143
rule_id: 10Uo39
version_id: LjTkgle
url: https://semgrep.dev/playground/r/LjTkgle/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret
origin: community
languages:
- javascript
- typescript
severity: WARNING
patterns:
- pattern-either:
- pattern-inside: |
$SESSION = require('express-session');
...
- pattern-inside: |
import $SESSION from 'express-session'
...
- pattern-inside: |
import {..., $SESSION, ...} from 'express-session'
...
- pattern-inside: |
import * as $SESSION from 'express-session'
...
- patterns:
- pattern-either:
- pattern-inside: $APP.use($SESSION({...}))
- pattern: |
$SECRET = $VALUE
...
$APP.use($SESSION($SECRET))
- pattern: |
secret: '$Y'
- id: javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization
message: The following function call $SER.$FUNC accepts user controlled data which
can result in Remote Code Execution (RCE) through Object Deserialization. It is
recommended to use secure data processing alternatives such as JSON.parse() and
Buffer.from().
options:
interfile: true
metadata:
interfile: true
technology:
- express
category: security
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Deserialization_Cheat_Sheet.html
source_rule_url:
- https://github.com/ajinabraham/njsscan/blob/75bfbeb9c8d72999e4d527dfa2548f7f0f3cc48a/njsscan/rules/semantic_grep/eval/eval_deserialize.yaml
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization
shortlink: https://sg.run/8W5j
semgrep.dev:
rule:
r_id: 22084
rv_id: 1263145
rule_id: 9AUyqj
version_id: gETB7nD
url: https://semgrep.dev/playground/r/gETB7nD/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
- pattern: files.$ANYTHING.data.toString('utf8')
- pattern: files.$ANYTHING['data'].toString('utf8')
pattern-sinks:
- pattern-either:
- patterns:
- pattern-either:
- pattern-inside: |
$SER = require('$IMPORT')
...
- pattern-inside: |
import $SER from '$IMPORT'
...
- pattern-inside: |
import * as $SER from '$IMPORT'
...
- metavariable-regex:
metavariable: $IMPORT
regex: ^(node-serialize|serialize-to-js)$
- pattern: $SER.$FUNC(...)
- metavariable-regex:
metavariable: $FUNC
regex: ^(unserialize|deserialize)$
- id: javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection
message: Detected a sequelize statement that is tainted by user-input. This could
lead to SQL injection if the variable is user-controlled and is not properly sanitized.
In order to prevent SQL injection, it is recommended to use parameterized queries
or prepared statements.
options:
interfile: true
metadata:
interfile: true
references:
- https://sequelize.org/docs/v6/core-concepts/raw-queries/#replacements
category: security
technology:
- express
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection
shortlink: https://sg.run/gjoe
semgrep.dev:
rule:
r_id: 22085
rv_id: 1263241
rule_id: yyU0GX
version_id: nWT2Llx
url: https://semgrep.dev/playground/r/nWT2Llx/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection
origin: community
languages:
- javascript
- typescript
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, $RES) {...}
- pattern-inside: function ... ($REQ, $RES, $NEXT) {...}
- patterns:
- pattern-either:
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...})
- pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...})
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|head|delete|options)$
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- pattern: $REQ.files.$ANYTHING.data.toString('utf8')
- pattern: $REQ.files.$ANYTHING['data'].toString('utf8')
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>
{...}
- pattern-inside: |
({ $REQ }: Request,$RES: Response) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
- pattern: files.$ANYTHING.data.toString('utf8')
- pattern: files.$ANYTHING['data'].toString('utf8')
pattern-sinks:
- pattern-either:
- patterns:
- pattern-either:
- pattern: sequelize.query($QUERY,...)
- pattern: $DB.sequelize.query($QUERY,...)
- focus-metavariable: $QUERY
pattern-sanitizers:
- pattern-either:
- pattern: parseInt(...)
- pattern: $FUNC. ... .hash(...)
- id: javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing
message: Directory listing/indexing is enabled, which may lead to disclosure of
sensitive directories and files. It is recommended to disable directory listing
unless it is a public resource. If you need directory listing, ensure that sensitive
files are inaccessible when querying the resource.
options:
interfile: true
metadata:
interfile: true
cwe:
- 'CWE-548: Exposure of Information Through Directory Listing'
owasp:
- A06:2017 - Security Misconfiguration
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
category: security
technology:
- express
references:
- https://www.npmjs.com/package/serve-index
- https://www.acunetix.com/blog/articles/directory-listing-information-disclosure/
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing
shortlink: https://sg.run/DX2G
semgrep.dev:
rule:
r_id: 22552
rv_id: 1263129
rule_id: x8UqEb
version_id: rxTAKGb
url: https://semgrep.dev/playground/r/rxTAKGb/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing
origin: community
languages:
- javascript
- typescript
severity: WARNING
patterns:
- pattern-either:
- pattern: |
$APP.use(require('serve-index')(...))
- patterns:
- pattern-either:
- pattern-inside: |
$SERVEINDEX = require('serve-index')
...
- pattern-inside: |
import $SERVEINDEX from 'serve-index'
...
- pattern-inside: |
import * as $SERVEINDEX from 'serve-index'
...
- pattern-either:
- patterns:
- pattern-inside: |
$VALUE = $SERVEINDEX(...)
...
- pattern: |
$VALUE(...)
- pattern: |
$APP.use(..., $SERVEINDEX(...), ...)
- id: javascript.express.security.audit.express-ssrf.express-ssrf
message: 'The following request $REQUEST.$METHOD() was found to be crafted from
user-input `$REQ` which can lead to Server-Side Request Forgery (SSRF) vulnerabilities.
It is recommended where possible to not allow user-input to craft the base request,
but to be treated as part of the path or query parameter. When user-input is necessary
to craft the request, it is recommeneded to follow OWASP best practices to prevent
abuse. '
metadata:
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
technology:
- express
category: security
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/javascript.express.security.audit.express-ssrf.express-ssrf
shortlink: https://sg.run/0PNw
semgrep.dev:
rule:
r_id: 22554
rv_id: 1263144
rule_id: eqU9l2
version_id: 8KT5rBr
url: https://semgrep.dev/playground/r/8KT5rBr/javascript.express.security.audit.express-ssrf.express-ssrf
origin: community
languages:
- javascript
- typescript
severity: WARNING
mode: taint
options:
taint_unify_mvars: true
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: function ... ($REQ, ...) {...}
- pattern-either:
- pattern: $REQ.query
- pattern: $REQ.body
- pattern: $REQ.params
- pattern: $REQ.cookies
- pattern: $REQ.headers
- patterns:
- pattern-either:
- pattern-inside: |
({ $REQ }: Request,...) =>
{...}
- pattern-inside: |
({ $REQ }: $EXPRESS.Request,...) => {...}
- focus-metavariable: $REQ
- pattern-either:
- pattern: params
- pattern: query
- pattern: cookies
- pattern: headers
- pattern: body
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
$REQUEST = require('request')
...
- pattern-inside: |
import * as $REQUEST from 'request'
...
- pattern-inside: |
import $REQUEST from 'request'
...
- pattern-either:
- pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE)
- pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE + $...A)
- pattern: $REQUEST.$METHOD(`$HTTP${$REQ. ... .$VALUE}...`)
- pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...])
- pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...] + $...A)
- pattern: $REQUEST.$METHOD(`$HTTP${$REQ.$VALUE[...]}...`)
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|patch|del|head|delete)$
- metavariable-regex:
metavariable: $HTTP
regex: ^(https?:\/\/|//)$
- pattern-either:
- pattern: $REQ. ... .$VALUE
- patterns:
- pattern-either:
- pattern-inside: |
$REQUEST = require('request')
...
- pattern-inside: |
import * as $REQUEST from 'request'
...
- pattern-inside: |
import $REQUEST from 'request'
...
- pattern-either:
- pattern: $REQUEST.$METHOD($REQ. ... .$VALUE,...)
- pattern: $REQUEST.$METHOD($REQ. ... .$VALUE + $...A,...)
- pattern: $REQUEST.$METHOD(`${$REQ. ... .$VALUE}...`,...)
- pattern: $REQ. ... .$VALUE
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|patch|del|head|delete)$
- patterns:
- pattern-either:
- pattern-inside: |
$REQUEST = require('request')
...
- pattern-inside: |
import * as $REQUEST from 'request'
...
- pattern-inside: |
import $REQUEST from 'request'
...
- pattern-either:
- pattern: $REQUEST.$METHOD($REQ.$VALUE['...'],...)
- pattern: $REQUEST.$METHOD($REQ.$VALUE['...'] + $...A,...)
- pattern: $REQUEST.$METHOD(`${$REQ.$VALUE['...']}...`,...)
- pattern: $REQ.$VALUE
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|patch|del|head|delete)$
- patterns:
- pattern-either:
- pattern-inside: |
$REQUEST = require('request')
...
- pattern-inside: |
import * as $REQUEST from 'request'
...
- pattern-inside: |
import $REQUEST from 'request'
...
- pattern-either:
- pattern-inside: |
$ASSIGN = $REQ. ... .$VALUE
...
- pattern-inside: |
$ASSIGN = $REQ. ... .$VALUE['...']
...
- pattern-inside: |
$ASSIGN = $REQ. ... .$VALUE + $...A
...
- pattern-inside: "$ASSIGN = $REQ. ... .$VALUE['...'] + $...A\n... \n"
- pattern-inside: |
$ASSIGN = `${$REQ. ... .$VALUE}...`
...
- pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE['...']}...`\n... \n"
- patterns:
- pattern-either:
- pattern-inside: |
$ASSIGN = "$HTTP"+ $REQ. ... .$VALUE
...
- pattern-inside: |
$ASSIGN = "$HTTP"+$REQ. ... .$VALUE + $...A
...
- pattern-inside: |
$ASSIGN = "$HTTP"+$REQ.$VALUE[...]
...
- pattern-inside: |
$ASSIGN = "$HTTP"+$REQ.$VALUE[...] + $...A
...
- pattern-inside: |
$ASSIGN = `$HTTP${$REQ.$VALUE[...]}...`
...
- metavariable-regex:
metavariable: $HTTP
regex: ^(https?:\/\/|//)$
- pattern-either:
- pattern: $REQUEST.$METHOD($ASSIGN,...)
- pattern: $REQUEST.$METHOD($ASSIGN + $...FOO,...)
- pattern: $REQUEST.$METHOD(`${$ASSIGN}...`,...)
- patterns:
- pattern-either:
- pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN,...)
- pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN + $...A,...)
- pattern: $REQUEST.$METHOD(`$HTTP${$ASSIGN}...`,...)
- metavariable-regex:
metavariable: $HTTP
regex: ^(https?:\/\/|//)$
- pattern: $ASSIGN
- metavariable-regex:
metavariable: $METHOD
regex: ^(get|post|put|patch|del|head|delete)$
- id: terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled
message: Ensure that App service enables detailed error messages
patterns:
- pattern: resource
- pattern-not-inside: |
resource "azurerm_app_service" "..." {
...
logs {
...
detailed_error_messages_enabled = true
...
}
...
}
- pattern-inside: |
resource "azurerm_app_service" "..." {
...
}
metadata:
owasp:
- A10:2017 - Insufficient Logging & Monitoring
- A09:2021 - Security Logging and Monitoring Failures
- A09:2025 - Security Logging & Alerting Failures
cwe:
- 'CWE-778: Insufficient Logging'
category: security
technology:
- terraform
- azure
references:
- https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insufficient Logging
source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled
shortlink: https://sg.run/pA1g
semgrep.dev:
rule:
r_id: 23962
rv_id: 1263762
rule_id: bwU1Eg
version_id: DkTRbr5
url: https://semgrep.dev/playground/r/DkTRbr5/terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only
message: Ensure web app redirects all HTTP traffic to HTTPS in Azure App Service
Slot
patterns:
- pattern: resource
- pattern-not-inside: |
resource "azurerm_app_service" "..." {
...
https_only = true
...
}
- pattern-inside: |
resource "azurerm_app_service" "..." {
...
}
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
category: security
technology:
- terraform
- azure
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only
shortlink: https://sg.run/1g9w
semgrep.dev:
rule:
r_id: 23966
rv_id: 1263766
rule_id: x8UZRP
version_id: qkTR78q
url: https://semgrep.dev/playground/r/qkTR78q/terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version
message: Ensure web app is using the latest version of TLS encryption
patterns:
- pattern-either:
- pattern: |
"1.0"
- pattern: |
"1.1"
- pattern-inside: min_tls_version = ...
- pattern-inside: |
$RESOURCE "azurerm_app_service" "..." {
...
}
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
category: security
technology:
- terraform
- azure
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version
shortlink: https://sg.run/rDwn
semgrep.dev:
rule:
r_id: 23969
rv_id: 1263769
rule_id: v8UNL7
version_id: 6xT29gv
url: https://semgrep.dev/playground/r/6xT29gv/terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date
message: Ensure that the expiration date is set on all keys
patterns:
- pattern: resource
- pattern-not-inside: |
resource "azurerm_key_vault_key" "..." {
...
expiration_date = "..."
...
}
- pattern-inside: |
resource "azurerm_key_vault_key" "..." {
...
}
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
cwe:
- 'CWE-320: CWE CATEGORY: Key Management Errors'
category: security
technology:
- terraform
- azure
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date
shortlink: https://sg.run/J1vw
semgrep.dev:
rule:
r_id: 23990
rv_id: 946834
rule_id: 0oUlgp
version_id: pZTNGkl
url: https://semgrep.dev/playground/r/pZTNGkl/terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version
message: Ensure MSSQL is using the latest version of TLS encryption
patterns:
- pattern-either:
- pattern: |
"1.0"
- pattern: |
"1.1"
- pattern-inside: minimum_tls_version = ...
- pattern-inside: |
$RESOURCE "azurerm_mssql_server" "..." {
...
}
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
category: security
technology:
- terraform
- azure
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version
shortlink: https://sg.run/B1lW
semgrep.dev:
rule:
r_id: 23995
rv_id: 1263784
rule_id: 6JUJG8
version_id: xyTjzeR
url: https://semgrep.dev/playground/r/xyTjzeR/terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled
message: Ensure that MySQL server enables infrastructure encryption
patterns:
- pattern: resource
- pattern-inside: |
resource "azurerm_mysql_server" "..." {
...
}
- pattern-not-inside: |
resource "azurerm_mysql_server" "..." {
...
infrastructure_encryption_enabled = true
...
}
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
cwe:
- 'CWE-320: CWE CATEGORY: Key Management Errors'
category: security
technology:
- terraform
- azure
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled
shortlink: https://sg.run/Dd6Y
semgrep.dev:
rule:
r_id: 23996
rv_id: 946840
rule_id: oqUloL
version_id: yeT0vBn
url: https://semgrep.dev/playground/r/yeT0vBn/terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version
message: Ensure MySQL is using the latest version of TLS encryption
patterns:
- pattern-either:
- pattern: |
"TLS1_0"
- pattern: |
"TLS1_1"
- pattern-inside: ssl_minimal_tls_version_enforced = ...
- pattern-inside: |
$RESOURCE "azurerm_mysql_server" "..." {
...
}
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
category: security
technology:
- terraform
- azure
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version
shortlink: https://sg.run/WR44
semgrep.dev:
rule:
r_id: 23997
rv_id: 1263785
rule_id: zdU8NN
version_id: O9TpxWE
url: https://semgrep.dev/playground/r/O9TpxWE/terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version
origin: community
languages:
- hcl
severity: WARNING
- id: go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage
message: Detected usage of dangerous method $METHOD which does not escape inputs
(see link in references). If the argument is user-controlled, this can lead to
SQL injection. When using $METHOD function, do not trust user-submitted data and
only allow approved list of input (possibly, use an allowlist approach).
severity: WARNING
languages:
- go
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
($REQUEST : http.Request).$ANYTHING
- pattern: |
($REQUEST : *http.Request).$ANYTHING
- metavariable-regex:
metavariable: $ANYTHING
regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$
pattern-sinks:
- patterns:
- pattern-inside: |
import ("gorm.io/gorm")
...
- patterns:
- pattern-inside: |
func $VAL(..., $GORM *gorm.DB,... ) {
...
}
- pattern-either:
- pattern: |
$GORM. ... .$METHOD($VALUE)
- pattern: |
$DB := $GORM. ... .$ANYTHING(...)
...
$DB. ... .$METHOD($VALUE)
- focus-metavariable: $VALUE
- metavariable-regex:
metavariable: $METHOD
regex: ^(Order|Exec|Raw|Group|Having|Distinct|Select|Pluck)$
pattern-sanitizers:
- pattern-either:
- pattern: strconv.Atoi(...)
- pattern: |
($X: bool)
options:
interfile: true
metadata:
category: security
technology:
- gorm
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://gorm.io/docs/security.html#SQL-injection-Methods
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
confidence: HIGH
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage
shortlink: https://sg.run/R4qg
semgrep.dev:
rule:
r_id: 24693
rv_id: 1262915
rule_id: AbU5o3
version_id: l4TJRJK
url: https://semgrep.dev/playground/r/l4TJRJK/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage
origin: community
- id: yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value
patterns:
- pattern-either:
- pattern: |
spec:
...
securityContext:
...
runAsNonRoot: $VALUE
- patterns:
- pattern-inside: |
containers:
...
- pattern: |
image: ...
...
securityContext:
...
runAsNonRoot: $VALUE
- metavariable-pattern:
metavariable: $VALUE
pattern: |
false
- focus-metavariable: $VALUE
fix: |
true
message: When running containers in Kubernetes, it's important to ensure that they are
properly secured to prevent privilege escalation attacks. One potential vulnerability
is when a container is allowed to run applications as the root user, which could
allow an attacker to gain access to sensitive resources. To mitigate this risk,
it's recommended to add a `securityContext` to the container, with the parameter
`runAsNonRoot` set to `true`. This will ensure that the container runs as a non-root
user, limiting the damage that could be caused by any potential attacks. By adding
a `securityContext` to the container in your Kubernetes pod, you can help to
ensure that your containerized applications are more secure and less vulnerable
to privilege escalation attacks.
metadata:
references:
- https://kubernetes.io/blog/2016/08/security-best-practices-kubernetes-deployment/
- https://kubernetes.io/docs/concepts/policy/pod-security-policy/
- https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-2-set-a-user
cwe:
- 'CWE-250: Execution with Unnecessary Privileges'
owasp:
- A05:2021 - Security Misconfiguration
- A06:2017 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
category: security
technology:
- kubernetes
subcategory:
- audit
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value
shortlink: https://sg.run/D9No
semgrep.dev:
rule:
r_id: 26096
rv_id: 1263939
rule_id: L1UAxy
version_id: NdTzyj8
url: https://semgrep.dev/playground/r/NdTzyj8/yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value
origin: community
languages:
- yaml
severity: INFO
- id: csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization
message: Anonymous access shouldn't be allowed unless explicit by design. Access
control checks are missing and potentially can be bypassed. This finding violates
the principle of least privilege or deny by default, where access should only
be permitted for a specific set of roles or conforms to a custom policy or users.
severity: INFO
metadata:
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
category: security
cwe:
- 'CWE-862: Missing Authorization'
cwe2021-top25: true
cwe2022-top25: true
cwe2023-top25: true
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
- https://cwe.mitre.org/data/definitions/862.html
- https://docs.microsoft.com/en-us/aspnet/core/security/authorization/simple?view=aspnetcore-7.0
subcategory:
- vuln
technology:
- .net
- mvc
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization
shortlink: https://sg.run/Z8GA
semgrep.dev:
rule:
r_id: 26335
rv_id: 1262615
rule_id: eqU32Y
version_id: o5TbD41
url: https://semgrep.dev/playground/r/o5TbD41/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization
origin: community
languages:
- csharp
patterns:
- pattern: |
public class $CLASS : Controller {
...
}
- pattern-inside: |
using Microsoft.AspNetCore.Mvc;
...
- pattern-not: |
[AllowAnonymous]
public class $CLASS : Controller {
...
}
- pattern-not: |
[Authorize]
public class $CLASS : Controller {
...
}
- pattern-not: |
[Authorize(Roles = ...)]
public class $CLASS : Controller {
...
}
- pattern-not: |
[Authorize(Policy = ...)]
public class $CLASS : Controller {
...
}
- id: csharp.dotnet.security.audit.open-directory-listing.open-directory-listing
message: An open directory listing is potentially exposed, potentially revealing
sensitive information to attackers.
severity: INFO
metadata:
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
category: security
cwe:
- 'CWE-548: Exposure of Information Through Directory Listing'
owasp:
- A06:2017 - Security Misconfiguration
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://cwe.mitre.org/data/definitions/548.html
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration/
- https://docs.microsoft.com/en-us/aspnet/core/fundamentals/static-files?view=aspnetcore-7.0#directory-browsing
subcategory:
- vuln
technology:
- .net
- mvc
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/csharp.dotnet.security.audit.open-directory-listing.open-directory-listing
shortlink: https://sg.run/n0y1
semgrep.dev:
rule:
r_id: 26336
rv_id: 1262616
rule_id: v8U8Ab
version_id: zyTb2Y2
url: https://semgrep.dev/playground/r/zyTb2Y2/csharp.dotnet.security.audit.open-directory-listing.open-directory-listing
origin: community
languages:
- csharp
patterns:
- pattern-either:
- pattern: (IApplicationBuilder $APP).UseDirectoryBrowser(...);
- pattern: $BUILDER.Services.AddDirectoryBrowser(...);
- pattern-inside: |
public void Configure(...) {
...
}
- id: csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token
patterns:
- pattern: RequireSignedTokens = false
- pattern-inside: |
new TokenValidationParameters {
...
}
fix: RequireSignedTokens = true
message: Accepting unsigned security tokens as valid security tokens allows an attacker
to remove its signature and potentially forge an identity. As a fix, set RequireSignedTokens
to be true.
metadata:
category: security
technology:
- csharp
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-347: Improper Verification of Cryptographic Signature'
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures/
- https://cwe.mitre.org/data/definitions/347
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token
shortlink: https://sg.run/pqzN
semgrep.dev:
rule:
r_id: 26718
rv_id: 1262631
rule_id: KxUGLw
version_id: e1Tyjrz
url: https://semgrep.dev/playground/r/e1Tyjrz/csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token
origin: community
languages:
- csharp
severity: ERROR
- id: csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure
patterns:
- pattern: $APP.UseDeveloperExceptionPage(...);
- pattern-not-inside: |
if ($ENV.IsDevelopment(...)) {
...
}
- pattern-not-inside: |
if ($ENV.EnvironmentName == "Development") {
...
}
message: Stacktrace information is displayed in a non-Development environment. Accidentally
disclosing sensitive stack trace information in a production environment aids
an attacker in reconnaissance and information gathering.
metadata:
category: security
technology:
- csharp
owasp:
- A06:2017 - Security Misconfiguration
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
cwe:
- 'CWE-209: Generation of Error Message Containing Sensitive Information'
references:
- https://cwe.mitre.org/data/definitions/209.html
- https://owasp.org/Top10/A04_2021-Insecure_Design/
subcategory:
- audit
likelihood: LOW
impact: LOW
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure
shortlink: https://sg.run/XvkA
semgrep.dev:
rule:
r_id: 26720
rv_id: 1262653
rule_id: lBU6Dv
version_id: 0bTKzrB
url: https://semgrep.dev/playground/r/0bTKzrB/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure
origin: community
languages:
- csharp
severity: WARNING
- id: csharp.dotnet.security.audit.mass-assignment.mass-assignment
message: Mass assignment or Autobinding vulnerability in code allows an attacker
to execute over-posting attacks, which could create a new parameter in the binding
request and manipulate the underlying object in the application.
severity: WARNING
metadata:
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
category: security
cwe:
- 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object
Attributes'
owasp:
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
references:
- https://cwe.mitre.org/data/definitions/915.html
- https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa6-mass-assignment.md
subcategory:
- vuln
technology:
- .net
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mass Assignment
source: https://semgrep.dev/r/csharp.dotnet.security.audit.mass-assignment.mass-assignment
shortlink: https://sg.run/7B3e
semgrep.dev:
rule:
r_id: 26838
rv_id: 1262613
rule_id: x8Up5B
version_id: YDTZeD9
url: https://semgrep.dev/playground/r/YDTZeD9/csharp.dotnet.security.audit.mass-assignment.mass-assignment
origin: community
languages:
- csharp
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
public IActionResult $METHOD(..., $TYPE $ARG, ...){
...
}
- pattern: |
public ActionResult $METHOD(..., $TYPE $ARG, ...){
...
}
- pattern-inside: |
using Microsoft.AspNetCore.Mvc;
...
- pattern-not: |
public IActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){
...
}
- pattern-not: |
public ActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){
...
}
- focus-metavariable: $ARG
pattern-sinks:
- pattern: View(...)
- id: python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: os.environ
- pattern: os.environ.get('$FOO', ...)
- pattern: os.environb
- pattern: os.environb.get('$FOO', ...)
- pattern: os.getenv('$ANYTHING', ...)
- pattern: os.getenvb('$ANYTHING', ...)
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: sys.argv
- pattern: sys.orig_argv
- patterns:
- pattern-inside: |
$PARSER = argparse.ArgumentParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-inside: |
$PARSER = optparse.OptionParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-either:
- pattern-inside: |
$OPTS, $ARGS = getopt.getopt(...)
...
- pattern-inside: |
$OPTS, $ARGS = getopt.gnu_getopt(...)
...
- pattern-either:
- patterns:
- pattern-inside: |
for $O, $A in $OPTS:
...
- pattern: $A
- pattern: $ARGS
pattern-sinks:
- pattern-either:
- patterns:
- pattern-not: $LOOP.subprocess_exec($PROTOCOL, "...", ...)
- pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["...",...], ...)
- pattern: $LOOP.subprocess_exec(...)
- patterns:
- pattern-not: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/",
"-c", "...", ...)
- pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/",
"-c",...)
- patterns:
- pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/",
"-c", "...", ...], ...)
- pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/",
"-c", ...], ...)
message: Detected subprocess function '$LOOP.subprocess_exec' with user controlled
data. You may consider using 'shlex.escape()'.
metadata:
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
references:
- https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec
- https://docs.python.org/3/library/shlex.html
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
category: security
technology:
- python
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args
shortlink: https://sg.run/Apjp
semgrep.dev:
rule:
r_id: 27250
rv_id: 1263460
rule_id: 7KUE1E
version_id: WrTqKXz
url: https://semgrep.dev/playground/r/WrTqKXz/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: os.environ
- pattern: os.environ.get('$FOO', ...)
- pattern: os.environb
- pattern: os.environb.get('$FOO', ...)
- pattern: os.getenv('$ANYTHING', ...)
- pattern: os.getenvb('$ANYTHING', ...)
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: sys.argv
- pattern: sys.orig_argv
- patterns:
- pattern-inside: |
$PARSER = argparse.ArgumentParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-inside: |
$PARSER = optparse.OptionParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-either:
- pattern-inside: |
$OPTS, $ARGS = getopt.getopt(...)
...
- pattern-inside: |
$OPTS, $ARGS = getopt.gnu_getopt(...)
...
- pattern-either:
- patterns:
- pattern-inside: |
for $O, $A in $OPTS:
...
- pattern: $A
- pattern: $ARGS
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: $LOOP.subprocess_shell($PROTOCOL, $CMD)
- pattern-inside: asyncio.subprocess.create_subprocess_shell($CMD, ...)
- pattern-inside: asyncio.create_subprocess_shell($CMD, ...)
- focus-metavariable: $CMD
- pattern-not-inside: |
$CMD = "..."
...
- pattern-not: $LOOP.subprocess_shell($PROTOCOL, "...")
- pattern-not: asyncio.subprocess.create_subprocess_shell("...", ...)
- pattern-not: asyncio.create_subprocess_shell("...", ...)
message: Detected asyncio subprocess function with user controlled data. You may
consider using 'shlex.escape()'.
metadata:
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
references:
- https://docs.python.org/3/library/asyncio-subprocess.html
- https://docs.python.org/3/library/shlex.html
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
category: security
technology:
- python
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args
shortlink: https://sg.run/Dx8Y
semgrep.dev:
rule:
r_id: 27252
rv_id: 1263462
rule_id: 8GU5q3
version_id: K3TKkDn
url: https://semgrep.dev/playground/r/K3TKkDn/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: os.environ
- pattern: os.environ.get('$FOO', ...)
- pattern: os.environb
- pattern: os.environb.get('$FOO', ...)
- pattern: os.getenv('$ANYTHING', ...)
- pattern: os.getenvb('$ANYTHING', ...)
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: sys.argv
- pattern: sys.orig_argv
- patterns:
- pattern-inside: |
$PARSER = argparse.ArgumentParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-inside: |
$PARSER = optparse.OptionParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-either:
- pattern-inside: |
$OPTS, $ARGS = getopt.getopt(...)
...
- pattern-inside: |
$OPTS, $ARGS = getopt.gnu_getopt(...)
...
- pattern-either:
- patterns:
- pattern-inside: |
for $O, $A in $OPTS:
...
- pattern: $A
- pattern: $ARGS
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
$X = code.InteractiveConsole(...)
...
- pattern-inside: |
$X = code.InteractiveInterpreter(...)
...
- pattern-either:
- pattern-inside: |
$X.push($PAYLOAD,...)
- pattern-inside: |
$X.runsource($PAYLOAD,...)
- pattern-inside: |
$X.runcode(code.compile_command($PAYLOAD),...)
- pattern-inside: |
$PL = code.compile_command($PAYLOAD,...)
...
$X.runcode($PL,...)
- pattern: $PAYLOAD
- pattern-not: |
$X.push("...",...)
- pattern-not: |
$X.runsource("...",...)
- pattern-not: |
$X.runcode(code.compile_command("..."),...)
- pattern-not: |
$PL = code.compile_command("...",...)
...
$X.runcode($PL,...)
message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter
method. This is dangerous if external data can reach this function call because
it allows a malicious actor to run arbitrary Python code.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
category: security
technology:
- python
confidence: MEDIUM
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args
shortlink: https://sg.run/0Bgv
semgrep.dev:
rule:
r_id: 27254
rv_id: 1263464
rule_id: QrUG72
version_id: l4TJRK9
url: https://semgrep.dev/playground/r/l4TJRK9/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args
origin: community
severity: WARNING
languages:
- python
- id: python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: os.environ
- pattern: os.environ.get('$FOO', ...)
- pattern: os.environb
- pattern: os.environb.get('$FOO', ...)
- pattern: os.getenv('$ANYTHING', ...)
- pattern: os.getenvb('$ANYTHING', ...)
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: sys.argv
- pattern: sys.orig_argv
- patterns:
- pattern-inside: |
$PARSER = argparse.ArgumentParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-inside: |
$PARSER = optparse.OptionParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-either:
- pattern-inside: |
$OPTS, $ARGS = getopt.getopt(...)
...
- pattern-inside: |
$OPTS, $ARGS = getopt.gnu_getopt(...)
...
- pattern-either:
- patterns:
- pattern-inside: |
for $O, $A in $OPTS:
...
- pattern: $A
- pattern: $ARGS
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-not: os.$METHOD("...", ...)
- pattern: os.$METHOD(...)
- metavariable-regex:
metavariable: $METHOD
regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe)
- patterns:
- pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...)
- pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...)
- pattern: $CMD
- metavariable-regex:
metavariable: $METHOD
regex: (execv|execve|execvp|execvpe)
- metavariable-regex:
metavariable: $BASH
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
- patterns:
- pattern-not: os.$METHOD("...", $PATH, "...", "...",...)
- pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...)
- pattern: $CMD
- metavariable-regex:
metavariable: $METHOD
regex: (execl|execle|execlp|execlpe)
- metavariable-regex:
metavariable: $BASH
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
message: Found user controlled content when spawning a process. This is dangerous
because it allows a malicious actor to execute commands.
metadata:
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
confidence: MEDIUM
category: security
technology:
- python
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args
shortlink: https://sg.run/qL6z
semgrep.dev:
rule:
r_id: 27256
rv_id: 1263466
rule_id: 4bUEAY
version_id: 6xT29l6
url: https://semgrep.dev/playground/r/6xT29l6/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: os.environ
- pattern: os.environ.get('$FOO', ...)
- pattern: os.environb
- pattern: os.environb.get('$FOO', ...)
- pattern: os.getenv('$ANYTHING', ...)
- pattern: os.getenvb('$ANYTHING', ...)
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: sys.argv
- pattern: sys.orig_argv
- patterns:
- pattern-inside: |
$PARSER = argparse.ArgumentParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-inside: |
$PARSER = optparse.OptionParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-either:
- pattern-inside: |
$OPTS, $ARGS = getopt.getopt(...)
...
- pattern-inside: |
$OPTS, $ARGS = getopt.gnu_getopt(...)
...
- pattern-either:
- patterns:
- pattern-inside: |
for $O, $A in $OPTS:
...
- pattern: $A
- pattern: $ARGS
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-not: os.$METHOD($MODE, "...", ...)
- pattern-inside: os.$METHOD($MODE, $CMD, ...)
- pattern: $CMD
- metavariable-regex:
metavariable: $METHOD
regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile)
- patterns:
- pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...)
- pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...)
- pattern: $CMD
- metavariable-regex:
metavariable: $METHOD
regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp)
- metavariable-regex:
metavariable: $BASH
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
- patterns:
- pattern-not: os.$METHOD($MODE, "...", "...", "...", ...)
- pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...)
- pattern: $CMD
- metavariable-regex:
metavariable: $METHOD
regex: (spawnl|spawnle|spawnlp|spawnlpe)
- metavariable-regex:
metavariable: $BASH
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
message: Found user controlled content when spawning a process. This is dangerous
because it allows a malicious actor to execute commands.
metadata:
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
category: security
technology:
- python
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args
shortlink: https://sg.run/Y3Ke
semgrep.dev:
rule:
r_id: 27258
rv_id: 1263468
rule_id: JDUz34
version_id: zyTb2wn
url: https://semgrep.dev/playground/r/zyTb2wn/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: os.environ
- pattern: os.environ.get('$FOO', ...)
- pattern: os.environb
- pattern: os.environb.get('$FOO', ...)
- pattern: os.getenv('$ANYTHING', ...)
- pattern: os.getenvb('$ANYTHING', ...)
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: sys.argv
- pattern: sys.orig_argv
- patterns:
- pattern-inside: |
$PARSER = argparse.ArgumentParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-inside: |
$PARSER = optparse.OptionParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-either:
- pattern-inside: |
$OPTS, $ARGS = getopt.getopt(...)
...
- pattern-inside: |
$OPTS, $ARGS = getopt.gnu_getopt(...)
...
- pattern-either:
- patterns:
- pattern-inside: |
for $O, $A in $OPTS:
...
- pattern: $A
- pattern: $ARGS
pattern-sinks:
- patterns:
- pattern-inside: |
_xxsubinterpreters.run_string($ID, $PAYLOAD, ...)
- pattern-not: |
_xxsubinterpreters.run_string($ID, "...", ...)
- pattern: $PAYLOAD
message: Found user controlled content in `run_string`. This is dangerous because
it allows a malicious actor to run arbitrary Python code.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://bugs.python.org/issue43472
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
category: security
technology:
- python
confidence: MEDIUM
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args
shortlink: https://sg.run/oLl9
semgrep.dev:
rule:
r_id: 27260
rv_id: 1409404
rule_id: GdUkxO
version_id: DkTwBzO
url: https://semgrep.dev/playground/r/DkTwBzO/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args
origin: community
severity: WARNING
languages:
- python
- id: python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args
mode: taint
options:
symbolic_propagation: true
pattern-sanitizers:
- pattern: shlex.quote(...)
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: os.environ
- pattern: os.environ.get('$FOO', ...)
- pattern: os.environb
- pattern: os.environb.get('$FOO', ...)
- pattern: os.getenv('$ANYTHING', ...)
- pattern: os.getenvb('$ANYTHING', ...)
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: sys.argv
- pattern: sys.orig_argv
- patterns:
- pattern-inside: |
$PARSER = argparse.ArgumentParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-inside: |
$PARSER = optparse.OptionParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-either:
- pattern-inside: |
$OPTS, $ARGS = getopt.getopt(...)
...
- pattern-inside: |
$OPTS, $ARGS = getopt.gnu_getopt(...)
...
- pattern-either:
- patterns:
- pattern-inside: |
for $O, $A in $OPTS:
...
- pattern: $A
- pattern: $ARGS
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-not: subprocess.$FUNC("...", ...)
- pattern-not: subprocess.$FUNC(["...",...], ...)
- pattern-not: subprocess.$FUNC(("...",...), ...)
- pattern-not: subprocess.CalledProcessError(...)
- pattern-not: subprocess.SubprocessError(...)
- pattern: subprocess.$FUNC($CMD, ...)
- patterns:
- pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...)
- pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD)
- patterns:
- pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...)
- pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...)
- pattern-either:
- pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD],
...)
- pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD),
...)
- patterns:
- pattern-not: subprocess.$FUNC("=~/(python)/","...",...)
- pattern: subprocess.$FUNC("=~/(python)/", $CMD)
- patterns:
- pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...)
- pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...)
- pattern-either:
- pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...)
- pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...)
- focus-metavariable: $CMD
message: Detected subprocess function '$FUNC' with user controlled data. A malicious
actor could leverage this to perform command injection. You may consider using
'shlex.quote()'.
metadata:
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
references:
- https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess
- https://docs.python.org/3/library/subprocess.html
- https://docs.python.org/3/library/shlex.html
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
category: security
technology:
- python
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args
shortlink: https://sg.run/pLGg
semgrep.dev:
rule:
r_id: 27262
rv_id: 1263472
rule_id: AbUgrZ
version_id: jQTn54Y
url: https://semgrep.dev/playground/r/jQTn54Y/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: os.environ
- pattern: os.environ.get('$FOO', ...)
- pattern: os.environb
- pattern: os.environb.get('$FOO', ...)
- pattern: os.getenv('$ANYTHING', ...)
- pattern: os.getenvb('$ANYTHING', ...)
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: sys.argv
- pattern: sys.orig_argv
- patterns:
- pattern-inside: |
$PARSER = argparse.ArgumentParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-inside: |
$PARSER = optparse.OptionParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-either:
- pattern-inside: |
$OPTS, $ARGS = getopt.getopt(...)
...
- pattern-inside: |
$OPTS, $ARGS = getopt.gnu_getopt(...)
...
- pattern-either:
- patterns:
- pattern-inside: |
for $O, $A in $OPTS:
...
- pattern: $A
- pattern: $ARGS
pattern-sinks:
- patterns:
- pattern-not: os.$W("...", ...)
- pattern-either:
- pattern: os.system(...)
- pattern: |
$X = __import__("os")
...
$X.system(...)
- pattern: |
$X = __import__("os")
...
getattr($X, "system")(...)
- pattern: |
$X = getattr(os, "system")
...
$X(...)
- pattern: |
$X = __import__("os")
...
$Y = getattr($X, "system")
...
$Y(...)
- pattern: os.popen(...)
- pattern: os.popen2(...)
- pattern: os.popen3(...)
- pattern: os.popen4(...)
message: Found user-controlled data used in a system call. This could allow a malicious
actor to execute commands. Use the 'subprocess' module instead, which is easier
to use without accidentally exposing a command injection vulnerability.
metadata:
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.2.4 Dyanmic Code Execution Features
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements
version: '4'
category: security
technology:
- python
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args
shortlink: https://sg.run/XR2K
semgrep.dev:
rule:
r_id: 27264
rv_id: 1263474
rule_id: DbUR9g
version_id: 9lT4bG4
url: https://semgrep.dev/playground/r/9lT4bG4/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: os.environ
- pattern: os.environ.get('$FOO', ...)
- pattern: os.environb
- pattern: os.environb.get('$FOO', ...)
- pattern: os.getenv('$ANYTHING', ...)
- pattern: os.getenvb('$ANYTHING', ...)
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: sys.argv
- pattern: sys.orig_argv
- patterns:
- pattern-inside: |
$PARSER = argparse.ArgumentParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-inside: |
$PARSER = optparse.OptionParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-either:
- pattern-inside: |
$OPTS, $ARGS = getopt.getopt(...)
...
- pattern-inside: |
$OPTS, $ARGS = getopt.gnu_getopt(...)
...
- pattern-either:
- patterns:
- pattern-inside: |
for $O, $A in $OPTS:
...
- pattern: $A
- pattern: $ARGS
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
_testcapi.run_in_subinterp($PAYLOAD, ...)
- pattern-inside: |
test.support.run_in_subinterp($PAYLOAD, ...)
- pattern: $PAYLOAD
- pattern-not: |
_testcapi.run_in_subinterp("...", ...)
- pattern-not: |
test.support.run_in_subinterp("...", ...)
message: Found user controlled content in `run_in_subinterp`. This is dangerous
because it allows a malicious actor to run arbitrary Python code.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
category: security
technology:
- python
confidence: MEDIUM
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args
shortlink: https://sg.run/1DLw
semgrep.dev:
rule:
r_id: 27266
rv_id: 1263476
rule_id: 0oUK7N
version_id: rxTAKpn
url: https://semgrep.dev/playground/r/rxTAKpn/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args
origin: community
severity: WARNING
languages:
- python
- id: python.lang.security.dangerous-code-run.dangerous-interactive-code-run
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: flask.request.form.get(...)
- pattern: flask.request.form[...]
- pattern: flask.request.args.get(...)
- pattern: flask.request.args[...]
- pattern: flask.request.values.get(...)
- pattern: flask.request.values[...]
- pattern: flask.request.cookies.get(...)
- pattern: flask.request.cookies[...]
- pattern: flask.request.stream
- pattern: flask.request.headers.get(...)
- pattern: flask.request.headers[...]
- pattern: flask.request.data
- pattern: flask.request.full_path
- pattern: flask.request.url
- pattern: flask.request.json
- pattern: flask.request.get_json()
- pattern: flask.request.view_args.get(...)
- pattern: flask.request.view_args[...]
- patterns:
- pattern-inside: |
@$APP.route(...)
def $FUNC(..., $ROUTEVAR, ...):
...
- focus-metavariable: $ROUTEVAR
- patterns:
- pattern-inside: |
def $FUNC(request, ...):
...
- pattern-either:
- pattern: request.$PROPERTY.get(...)
- pattern: request.$PROPERTY[...]
- patterns:
- pattern-either:
- pattern-inside: |
@rest_framework.decorators.api_view(...)
def $FUNC($REQ, ...):
...
- patterns:
- pattern-either:
- pattern-inside: |
class $VIEW(..., rest_framework.views.APIView, ...):
...
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
...):\n ... \n"
- pattern-inside: |
def $METHOD(self, $REQ, ...):
...
- metavariable-regex:
metavariable: $METHOD
regex: (get|post|put|patch|delete|head)
- pattern-either:
- pattern: $REQ.POST.get(...)
- pattern: $REQ.POST[...]
- pattern: $REQ.FILES.get(...)
- pattern: $REQ.FILES[...]
- pattern: $REQ.DATA.get(...)
- pattern: $REQ.DATA[...]
- pattern: $REQ.QUERY_PARAMS.get(...)
- pattern: $REQ.QUERY_PARAMS[...]
- pattern: $REQ.data.get(...)
- pattern: $REQ.data[...]
- pattern: $REQ.query_params.get(...)
- pattern: $REQ.query_params[...]
- pattern: $REQ.content_type
- pattern: $REQ.content_type
- pattern: $REQ.stream
- pattern: $REQ.stream
- patterns:
- pattern-either:
- pattern-inside: |
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.StreamRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.DatagramRequestHandler, ...):
...
- pattern-either:
- pattern: self.requestline
- pattern: self.path
- pattern: self.headers[...]
- pattern: self.headers.get(...)
- pattern: self.rfile
- patterns:
- pattern-inside: |
@pyramid.view.view_config( ... )
def $VIEW($REQ):
...
- pattern: $REQ.$ANYTHING
- pattern-not: $REQ.dbsession
pattern-sinks:
- patterns:
- pattern-either:
- pattern-inside: |
$X = code.InteractiveConsole(...)
...
- pattern-inside: |
$X = code.InteractiveInterpreter(...)
...
- pattern-either:
- pattern: |
$X.push($PAYLOAD,...)
- pattern: |
$X.runsource($PAYLOAD,...)
- pattern: |
$X.runcode(code.compile_command($PAYLOAD),...)
- pattern: |
$PL = code.compile_command($PAYLOAD,...)
...
$X.runcode($PL,...)
- focus-metavariable: $PAYLOAD
- pattern-not: |
$X.push("...",...)
- pattern-not: |
$X.runsource("...",...)
- pattern-not: |
$X.runcode(code.compile_command("..."),...)
- pattern-not: |
$PL = code.compile_command("...",...)
...
$X.runcode($PL,...)
message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter
method. This is dangerous if external data can reach this function call because
it allows a malicious actor to run arbitrary Python code.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
category: security
technology:
- python
confidence: MEDIUM
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.lang.security.dangerous-code-run.dangerous-interactive-code-run
shortlink: https://sg.run/9pRY
semgrep.dev:
rule:
r_id: 27267
rv_id: 1263521
rule_id: KxUKzx
version_id: l4TJRgo
url: https://semgrep.dev/playground/r/l4TJRgo/python.lang.security.dangerous-code-run.dangerous-interactive-code-run
origin: community
severity: WARNING
languages:
- python
- id: python.lang.security.dangerous-os-exec.dangerous-os-exec
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: flask.request.form.get(...)
- pattern: flask.request.form[...]
- pattern: flask.request.args.get(...)
- pattern: flask.request.args[...]
- pattern: flask.request.values.get(...)
- pattern: flask.request.values[...]
- pattern: flask.request.cookies.get(...)
- pattern: flask.request.cookies[...]
- pattern: flask.request.stream
- pattern: flask.request.headers.get(...)
- pattern: flask.request.headers[...]
- pattern: flask.request.data
- pattern: flask.request.full_path
- pattern: flask.request.url
- pattern: flask.request.json
- pattern: flask.request.get_json()
- pattern: flask.request.view_args.get(...)
- pattern: flask.request.view_args[...]
- patterns:
- pattern-inside: |
@$APP.route(...)
def $FUNC(..., $ROUTEVAR, ...):
...
- focus-metavariable: $ROUTEVAR
- patterns:
- pattern-inside: |
def $FUNC(request, ...):
...
- pattern-either:
- pattern: request.$PROPERTY.get(...)
- pattern: request.$PROPERTY[...]
- patterns:
- pattern-either:
- pattern-inside: |
@rest_framework.decorators.api_view(...)
def $FUNC($REQ, ...):
...
- patterns:
- pattern-either:
- pattern-inside: |
class $VIEW(..., rest_framework.views.APIView, ...):
...
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
...):\n ... \n"
- pattern-inside: |
def $METHOD(self, $REQ, ...):
...
- metavariable-regex:
metavariable: $METHOD
regex: (get|post|put|patch|delete|head)
- pattern-either:
- pattern: $REQ.POST.get(...)
- pattern: $REQ.POST[...]
- pattern: $REQ.FILES.get(...)
- pattern: $REQ.FILES[...]
- pattern: $REQ.DATA.get(...)
- pattern: $REQ.DATA[...]
- pattern: $REQ.QUERY_PARAMS.get(...)
- pattern: $REQ.QUERY_PARAMS[...]
- pattern: $REQ.data.get(...)
- pattern: $REQ.data[...]
- pattern: $REQ.query_params.get(...)
- pattern: $REQ.query_params[...]
- pattern: $REQ.content_type
- pattern: $REQ.content_type
- pattern: $REQ.stream
- pattern: $REQ.stream
- patterns:
- pattern-either:
- pattern-inside: |
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.StreamRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.DatagramRequestHandler, ...):
...
- pattern-either:
- pattern: self.requestline
- pattern: self.path
- pattern: self.headers[...]
- pattern: self.headers.get(...)
- pattern: self.rfile
- patterns:
- pattern-inside: |
@pyramid.view.view_config( ... )
def $VIEW($REQ):
...
- pattern: $REQ.$ANYTHING
- pattern-not: $REQ.dbsession
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-not: os.$METHOD("...", ...)
- pattern: os.$METHOD(...)
- metavariable-regex:
metavariable: $METHOD
regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe)
- patterns:
- pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...)
- pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...)
- pattern: $CMD
- metavariable-regex:
metavariable: $METHOD
regex: (execv|execve|execvp|execvpe)
- metavariable-regex:
metavariable: $BASH
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
- patterns:
- pattern-not: os.$METHOD("...", $PATH, "...", "...",...)
- pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...)
- pattern: $CMD
- metavariable-regex:
metavariable: $METHOD
regex: (execl|execle|execlp|execlpe)
- metavariable-regex:
metavariable: $BASH
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
message: Found user controlled content when spawning a process. This is dangerous
because it allows a malicious actor to execute commands.
metadata:
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
confidence: MEDIUM
category: security
technology:
- python
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.lang.security.dangerous-os-exec.dangerous-os-exec
shortlink: https://sg.run/yL9x
semgrep.dev:
rule:
r_id: 27268
rv_id: 1263523
rule_id: qNUR13
version_id: 6xT29rz
url: https://semgrep.dev/playground/r/6xT29rz/python.lang.security.dangerous-os-exec.dangerous-os-exec
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.dangerous-spawn-process.dangerous-spawn-process
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: flask.request.form.get(...)
- pattern: flask.request.form[...]
- pattern: flask.request.args.get(...)
- pattern: flask.request.args[...]
- pattern: flask.request.values.get(...)
- pattern: flask.request.values[...]
- pattern: flask.request.cookies.get(...)
- pattern: flask.request.cookies[...]
- pattern: flask.request.stream
- pattern: flask.request.headers.get(...)
- pattern: flask.request.headers[...]
- pattern: flask.request.data
- pattern: flask.request.full_path
- pattern: flask.request.url
- pattern: flask.request.json
- pattern: flask.request.get_json()
- pattern: flask.request.view_args.get(...)
- pattern: flask.request.view_args[...]
- patterns:
- pattern-inside: |
@$APP.route(...)
def $FUNC(..., $ROUTEVAR, ...):
...
- pattern: $ROUTEVAR
- patterns:
- pattern-inside: |
def $FUNC(request, ...):
...
- pattern-either:
- pattern: request.$PROPERTY.get(...)
- pattern: request.$PROPERTY[...]
- patterns:
- pattern-either:
- pattern-inside: |
@rest_framework.decorators.api_view(...)
def $FUNC($REQ, ...):
...
- patterns:
- pattern-either:
- pattern-inside: |
class $VIEW(..., rest_framework.views.APIView, ...):
...
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
...):\n ... \n"
- pattern-inside: |
def $METHOD(self, $REQ, ...):
...
- metavariable-regex:
metavariable: $METHOD
regex: (get|post|put|patch|delete|head)
- pattern-either:
- pattern: $REQ.POST.get(...)
- pattern: $REQ.POST[...]
- pattern: $REQ.FILES.get(...)
- pattern: $REQ.FILES[...]
- pattern: $REQ.DATA.get(...)
- pattern: $REQ.DATA[...]
- pattern: $REQ.QUERY_PARAMS.get(...)
- pattern: $REQ.QUERY_PARAMS[...]
- pattern: $REQ.data.get(...)
- pattern: $REQ.data[...]
- pattern: $REQ.query_params.get(...)
- pattern: $REQ.query_params[...]
- pattern: $REQ.content_type
- pattern: $REQ.content_type
- pattern: $REQ.stream
- pattern: $REQ.stream
- patterns:
- pattern-either:
- pattern-inside: |
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.StreamRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.DatagramRequestHandler, ...):
...
- pattern-either:
- pattern: self.requestline
- pattern: self.path
- pattern: self.headers[...]
- pattern: self.headers.get(...)
- pattern: self.rfile
- patterns:
- pattern-inside: |
@pyramid.view.view_config( ... )
def $VIEW($REQ):
...
- pattern: $REQ.$ANYTHING
- pattern-not: $REQ.dbsession
- patterns:
- pattern-either:
- pattern: os.environ['$ANYTHING']
- pattern: os.environ.get('$FOO', ...)
- pattern: os.environb['$ANYTHING']
- pattern: os.environb.get('$FOO', ...)
- pattern: os.getenv('$ANYTHING', ...)
- pattern: os.getenvb('$ANYTHING', ...)
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: sys.argv[...]
- pattern: sys.orig_argv[...]
- patterns:
- pattern-inside: |
$PARSER = argparse.ArgumentParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-inside: |
$PARSER = optparse.OptionParser(...)
...
- pattern-inside: |
$ARGS = $PARSER.parse_args()
- pattern: <... $ARGS ...>
- patterns:
- pattern-either:
- pattern-inside: |
$OPTS, $ARGS = getopt.getopt(...)
...
- pattern-inside: |
$OPTS, $ARGS = getopt.gnu_getopt(...)
...
- pattern-either:
- patterns:
- pattern-inside: |
for $O, $A in $OPTS:
...
- pattern: $A
- pattern: $ARGS
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-not: os.$METHOD($MODE, "...", ...)
- pattern-inside: os.$METHOD($MODE, $CMD, ...)
- pattern: $CMD
- metavariable-regex:
metavariable: $METHOD
regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile)
- patterns:
- pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...)
- pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...)
- pattern: $CMD
- metavariable-regex:
metavariable: $METHOD
regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp)
- metavariable-regex:
metavariable: $BASH
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
- patterns:
- pattern-not: os.$METHOD($MODE, "...", "...", "...", ...)
- pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...)
- pattern: $CMD
- metavariable-regex:
metavariable: $METHOD
regex: (spawnl|spawnle|spawnlp|spawnlpe)
- metavariable-regex:
metavariable: $BASH
regex: (.*)(sh|bash|ksh|csh|tcsh|zsh)
message: Found user controlled content when spawning a process. This is dangerous
because it allows a malicious actor to execute commands.
metadata:
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
category: security
technology:
- python
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.lang.security.dangerous-spawn-process.dangerous-spawn-process
shortlink: https://sg.run/r8Zn
semgrep.dev:
rule:
r_id: 27269
rv_id: 1263524
rule_id: lBUJrn
version_id: o5TbDO5
url: https://semgrep.dev/playground/r/o5TbDO5/python.lang.security.dangerous-spawn-process.dangerous-spawn-process
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: flask.request.form.get(...)
- pattern: flask.request.form[...]
- pattern: flask.request.args.get(...)
- pattern: flask.request.args[...]
- pattern: flask.request.values.get(...)
- pattern: flask.request.values[...]
- pattern: flask.request.cookies.get(...)
- pattern: flask.request.cookies[...]
- pattern: flask.request.stream
- pattern: flask.request.headers.get(...)
- pattern: flask.request.headers[...]
- pattern: flask.request.data
- pattern: flask.request.full_path
- pattern: flask.request.url
- pattern: flask.request.json
- pattern: flask.request.get_json()
- pattern: flask.request.view_args.get(...)
- pattern: flask.request.view_args[...]
- patterns:
- pattern-inside: |
@$APP.route(...)
def $FUNC(..., $ROUTEVAR, ...):
...
- focus-metavariable: $ROUTEVAR
- patterns:
- pattern-inside: |
def $FUNC(request, ...):
...
- pattern-either:
- pattern: request.$PROPERTY.get(...)
- pattern: request.$PROPERTY[...]
- patterns:
- pattern-either:
- pattern-inside: |
@rest_framework.decorators.api_view(...)
def $FUNC($REQ, ...):
...
- patterns:
- pattern-either:
- pattern-inside: |
class $VIEW(..., rest_framework.views.APIView, ...):
...
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
...):\n ... \n"
- pattern-inside: |
def $METHOD(self, $REQ, ...):
...
- metavariable-regex:
metavariable: $METHOD
regex: (get|post|put|patch|delete|head)
- pattern-either:
- pattern: $REQ.POST.get(...)
- pattern: $REQ.POST[...]
- pattern: $REQ.FILES.get(...)
- pattern: $REQ.FILES[...]
- pattern: $REQ.DATA.get(...)
- pattern: $REQ.DATA[...]
- pattern: $REQ.QUERY_PARAMS.get(...)
- pattern: $REQ.QUERY_PARAMS[...]
- pattern: $REQ.data.get(...)
- pattern: $REQ.data[...]
- pattern: $REQ.query_params.get(...)
- pattern: $REQ.query_params[...]
- pattern: $REQ.content_type
- pattern: $REQ.content_type
- pattern: $REQ.stream
- pattern: $REQ.stream
- patterns:
- pattern-either:
- pattern-inside: |
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.StreamRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.DatagramRequestHandler, ...):
...
- pattern-either:
- pattern: self.requestline
- pattern: self.path
- pattern: self.headers[...]
- pattern: self.headers.get(...)
- pattern: self.rfile
- patterns:
- pattern-inside: |
@pyramid.view.view_config( ... )
def $VIEW($REQ):
...
- pattern: $REQ.$ANYTHING
- pattern-not: $REQ.dbsession
pattern-sinks:
- patterns:
- pattern: |
_xxsubinterpreters.run_string($ID, $PAYLOAD, ...)
- pattern-not: |
_xxsubinterpreters.run_string($ID, "...", ...)
- focus-metavariable: $PAYLOAD
message: Found user controlled content in `run_string`. This is dangerous because
it allows a malicious actor to run arbitrary Python code.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://bugs.python.org/issue43472
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
category: security
technology:
- python
confidence: MEDIUM
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string
shortlink: https://sg.run/bPop
semgrep.dev:
rule:
r_id: 27270
rv_id: 1263525
rule_id: PeURWr
version_id: zyTb2OX
url: https://semgrep.dev/playground/r/zyTb2OX/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string
origin: community
severity: WARNING
languages:
- python
- id: python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: flask.request.form.get(...)
- pattern: flask.request.form[...]
- pattern: flask.request.args.get(...)
- pattern: flask.request.args[...]
- pattern: flask.request.values.get(...)
- pattern: flask.request.values[...]
- pattern: flask.request.cookies.get(...)
- pattern: flask.request.cookies[...]
- pattern: flask.request.stream
- pattern: flask.request.headers.get(...)
- pattern: flask.request.headers[...]
- pattern: flask.request.data
- pattern: flask.request.full_path
- pattern: flask.request.url
- pattern: flask.request.json
- pattern: flask.request.get_json()
- pattern: flask.request.view_args.get(...)
- pattern: flask.request.view_args[...]
- patterns:
- pattern-inside: |
@$APP.route(...)
def $FUNC(..., $ROUTEVAR, ...):
...
- focus-metavariable: $ROUTEVAR
- patterns:
- pattern-inside: |
def $FUNC(request, ...):
...
- pattern-either:
- pattern: request.$PROPERTY.get(...)
- pattern: request.$PROPERTY[...]
- patterns:
- pattern-either:
- pattern-inside: |
@rest_framework.decorators.api_view(...)
def $FUNC($REQ, ...):
...
- patterns:
- pattern-either:
- pattern-inside: |
class $VIEW(..., rest_framework.views.APIView, ...):
...
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
...):\n ... \n"
- pattern-inside: |
def $METHOD(self, $REQ, ...):
...
- metavariable-regex:
metavariable: $METHOD
regex: (get|post|put|patch|delete|head)
- pattern-either:
- pattern: $REQ.POST.get(...)
- pattern: $REQ.POST[...]
- pattern: $REQ.FILES.get(...)
- pattern: $REQ.FILES[...]
- pattern: $REQ.DATA.get(...)
- pattern: $REQ.DATA[...]
- pattern: $REQ.QUERY_PARAMS.get(...)
- pattern: $REQ.QUERY_PARAMS[...]
- pattern: $REQ.data.get(...)
- pattern: $REQ.data[...]
- pattern: $REQ.query_params.get(...)
- pattern: $REQ.query_params[...]
- pattern: $REQ.content_type
- pattern: $REQ.content_type
- pattern: $REQ.stream
- pattern: $REQ.stream
- patterns:
- pattern-either:
- pattern-inside: |
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.StreamRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.DatagramRequestHandler, ...):
...
- pattern-either:
- pattern: self.requestline
- pattern: self.path
- pattern: self.headers[...]
- pattern: self.headers.get(...)
- pattern: self.rfile
- patterns:
- pattern-inside: |
@pyramid.view.view_config( ... )
def $VIEW($REQ):
...
- pattern: $REQ.$ANYTHING
- pattern-not: $REQ.dbsession
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-not: subprocess.$FUNC("...", ...)
- pattern-not: subprocess.$FUNC(["...",...], ...)
- pattern-not: subprocess.$FUNC(("...",...), ...)
- pattern-not: subprocess.CalledProcessError(...)
- pattern-not: subprocess.SubprocessError(...)
- pattern: subprocess.$FUNC($CMD, ...)
- patterns:
- pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...)
- pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD)
- patterns:
- pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...)
- pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...)
- pattern-either:
- pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD],
...)
- pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD),
...)
- patterns:
- pattern-not: subprocess.$FUNC("=~/(python)/","...",...)
- pattern: subprocess.$FUNC("=~/(python)/", $CMD)
- patterns:
- pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...)
- pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...)
- pattern-either:
- pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...)
- pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...)
- focus-metavariable: $CMD
message: Detected subprocess function '$FUNC' with user controlled data. A malicious
actor could leverage this to perform command injection. You may consider using
'shlex.escape()'.
metadata:
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.3.8 OS Command Injection
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements
version: '4'
references:
- https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess
- https://docs.python.org/3/library/subprocess.html
- https://docs.python.org/3/library/shlex.html
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
category: security
technology:
- python
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use
shortlink: https://sg.run/NWxp
semgrep.dev:
rule:
r_id: 27271
rv_id: 1263526
rule_id: JDUz3R
version_id: pZT038J
url: https://semgrep.dev/playground/r/pZT038J/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.dangerous-system-call.dangerous-system-call
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: flask.request.form.get(...)
- pattern: flask.request.form[...]
- pattern: flask.request.args.get(...)
- pattern: flask.request.args[...]
- pattern: flask.request.values.get(...)
- pattern: flask.request.values[...]
- pattern: flask.request.cookies.get(...)
- pattern: flask.request.cookies[...]
- pattern: flask.request.stream
- pattern: flask.request.headers.get(...)
- pattern: flask.request.headers[...]
- pattern: flask.request.data
- pattern: flask.request.full_path
- pattern: flask.request.url
- pattern: flask.request.json
- pattern: flask.request.get_json()
- pattern: flask.request.view_args.get(...)
- pattern: flask.request.view_args[...]
- patterns:
- pattern-inside: |
@$APP.route(...)
def $FUNC(..., $ROUTEVAR, ...):
...
- focus-metavariable: $ROUTEVAR
- patterns:
- pattern-inside: |
def $FUNC(request, ...):
...
- pattern-either:
- pattern: request.$PROPERTY.get(...)
- pattern: request.$PROPERTY[...]
- patterns:
- pattern-either:
- pattern-inside: |
@rest_framework.decorators.api_view(...)
def $FUNC($REQ, ...):
...
- patterns:
- pattern-either:
- pattern-inside: |
class $VIEW(..., rest_framework.views.APIView, ...):
...
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
...):\n ... \n"
- pattern-inside: |
def $METHOD(self, $REQ, ...):
...
- metavariable-regex:
metavariable: $METHOD
regex: (get|post|put|patch|delete|head)
- pattern-either:
- pattern: $REQ.POST.get(...)
- pattern: $REQ.POST[...]
- pattern: $REQ.FILES.get(...)
- pattern: $REQ.FILES[...]
- pattern: $REQ.DATA.get(...)
- pattern: $REQ.DATA[...]
- pattern: $REQ.QUERY_PARAMS.get(...)
- pattern: $REQ.QUERY_PARAMS[...]
- pattern: $REQ.data.get(...)
- pattern: $REQ.data[...]
- pattern: $REQ.query_params.get(...)
- pattern: $REQ.query_params[...]
- pattern: $REQ.content_type
- pattern: $REQ.content_type
- pattern: $REQ.stream
- pattern: $REQ.stream
- patterns:
- pattern-either:
- pattern-inside: |
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.StreamRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.DatagramRequestHandler, ...):
...
- pattern-either:
- pattern: self.requestline
- pattern: self.path
- pattern: self.headers[...]
- pattern: self.headers.get(...)
- pattern: self.rfile
- patterns:
- pattern-inside: |
@pyramid.view.view_config( ... )
def $VIEW($REQ):
...
- pattern: $REQ.$ANYTHING
- pattern-not: $REQ.dbsession
pattern-sinks:
- patterns:
- pattern-not: os.$W("...", ...)
- pattern-either:
- pattern: os.system(...)
- pattern: getattr(os, "system")(...)
- pattern: __import__("os").system(...)
- pattern: getattr(__import__("os"), "system")(...)
- pattern: |
$X = __import__("os")
...
$X.system(...)
- pattern: |
$X = __import__("os")
...
getattr($X, "system")(...)
- pattern: |
$X = getattr(os, "system")
...
$X(...)
- pattern: |
$X = __import__("os")
...
$Y = getattr($X, "system")
...
$Y(...)
- pattern: os.popen(...)
- pattern: os.popen2(...)
- pattern: os.popen3(...)
- pattern: os.popen4(...)
message: Found user-controlled data used in a system call. This could allow a malicious
actor to execute commands. Use the 'subprocess' module instead, which is easier
to use without accidentally exposing a command injection vulnerability.
metadata:
source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
asvs:
section: 'V5: Validation, Sanitization and Encoding Verification Requirements'
control_id: 5.2.4 Dyanmic Code Execution Features
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements
version: '4'
category: security
technology:
- python
confidence: MEDIUM
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.lang.security.dangerous-system-call.dangerous-system-call
shortlink: https://sg.run/k0W7
semgrep.dev:
rule:
r_id: 27272
rv_id: 1263527
rule_id: 5rUoP1
version_id: 2KTv2Zn
url: https://semgrep.dev/playground/r/2KTv2Zn/python.lang.security.dangerous-system-call.dangerous-system-call
origin: community
languages:
- python
severity: ERROR
- id: python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: flask.request.form.get(...)
- pattern: flask.request.form[...]
- pattern: flask.request.args.get(...)
- pattern: flask.request.args[...]
- pattern: flask.request.values.get(...)
- pattern: flask.request.values[...]
- pattern: flask.request.cookies.get(...)
- pattern: flask.request.cookies[...]
- pattern: flask.request.stream
- pattern: flask.request.headers.get(...)
- pattern: flask.request.headers[...]
- pattern: flask.request.data
- pattern: flask.request.full_path
- pattern: flask.request.url
- pattern: flask.request.json
- pattern: flask.request.get_json()
- pattern: flask.request.view_args.get(...)
- pattern: flask.request.view_args[...]
- patterns:
- pattern-inside: |
@$APP.route(...)
def $FUNC(..., $ROUTEVAR, ...):
...
- focus-metavariable: $ROUTEVAR
- patterns:
- pattern-inside: |
def $FUNC(request, ...):
...
- pattern-either:
- pattern: request.$PROPERTY.get(...)
- pattern: request.$PROPERTY[...]
- patterns:
- pattern-either:
- pattern-inside: |
@rest_framework.decorators.api_view(...)
def $FUNC($REQ, ...):
...
- patterns:
- pattern-either:
- pattern-inside: |
class $VIEW(..., rest_framework.views.APIView, ...):
...
- pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView,
...):\n ... \n"
- pattern-inside: |
def $METHOD(self, $REQ, ...):
...
- metavariable-regex:
metavariable: $METHOD
regex: (get|post|put|patch|delete|head)
- pattern-either:
- pattern: $REQ.POST.get(...)
- pattern: $REQ.POST[...]
- pattern: $REQ.FILES.get(...)
- pattern: $REQ.FILES[...]
- pattern: $REQ.DATA.get(...)
- pattern: $REQ.DATA[...]
- pattern: $REQ.QUERY_PARAMS.get(...)
- pattern: $REQ.QUERY_PARAMS[...]
- pattern: $REQ.data.get(...)
- pattern: $REQ.data[...]
- pattern: $REQ.query_params.get(...)
- pattern: $REQ.query_params[...]
- pattern: $REQ.content_type
- pattern: $REQ.content_type
- pattern: $REQ.stream
- pattern: $REQ.stream
- patterns:
- pattern-either:
- pattern-inside: |
class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.StreamRequestHandler, ...):
...
- pattern-inside: |
class $SERVER(..., http.server.DatagramRequestHandler, ...):
...
- pattern-either:
- pattern: self.requestline
- pattern: self.path
- pattern: self.headers[...]
- pattern: self.headers.get(...)
- pattern: self.rfile
- patterns:
- pattern-inside: |
@pyramid.view.view_config( ... )
def $VIEW($REQ):
...
- pattern: $REQ.$ANYTHING
- pattern-not: $REQ.dbsession
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
_testcapi.run_in_subinterp($PAYLOAD, ...)
- pattern: |
test.support.run_in_subinterp($PAYLOAD, ...)
- focus-metavariable: $PAYLOAD
- pattern-not: |
_testcapi.run_in_subinterp("...", ...)
- pattern-not: |
test.support.run_in_subinterp("...", ...)
message: Found user controlled content in `run_in_subinterp`. This is dangerous
because it allows a malicious actor to run arbitrary Python code.
metadata:
cwe:
- 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code
(''Eval Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
category: security
technology:
- python
confidence: MEDIUM
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp
shortlink: https://sg.run/wLpY
semgrep.dev:
rule:
r_id: 27273
rv_id: 1263528
rule_id: GdUkxR
version_id: X0Tzy1e
url: https://semgrep.dev/playground/r/X0Tzy1e/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp
origin: community
severity: WARNING
languages:
- python
- id: csharp.dotnet.security.audit.xpath-injection.xpath-injection
message: XPath queries are constructed dynamically on user-controlled input. This
vulnerability in code could lead to an XPath Injection exploitation.
severity: ERROR
metadata:
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
category: security
cwe:
- 'CWE-643: Improper Neutralization of Data within XPath Expressions (''XPath
Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection/
- https://cwe.mitre.org/data/definitions/643.html
subcategory:
- vuln
technology:
- .net
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XPath Injection
source: https://semgrep.dev/r/csharp.dotnet.security.audit.xpath-injection.xpath-injection
shortlink: https://sg.run/4KP7
semgrep.dev:
rule:
r_id: 27400
rv_id: 1262618
rule_id: x8Uj2k
version_id: 2KTv2Pq
url: https://semgrep.dev/playground/r/2KTv2Pq/csharp.dotnet.security.audit.xpath-injection.xpath-injection
origin: community
languages:
- csharp
mode: taint
pattern-sources:
- pattern-either:
- pattern: $T $M($INPUT,...) {...}
- pattern: |
$T $M(...) {
...
string $INPUT;
}
pattern-sinks:
- pattern-either:
- pattern: XPathExpression $EXPR = $NAV.Compile("..." + $INPUT + "...");
- pattern: var $EXPR = $NAV.Compile("..." + $INPUT + "...");
- pattern: XPathNodeIterator $NODE = $NAV.Select("..." + $INPUT + "...");
- pattern: var $NODE = $NAV.Select("..." + $INPUT + "...");
- pattern: Object $OBJ = $NAV.Evaluate("..." + $INPUT + "...");
- pattern: var $OBJ = $NAV.Evaluate("..." + $INPUT + "...");
- id: csharp.dotnet.security.audit.ldap-injection.ldap-injection
message: LDAP queries are constructed dynamically on user-controlled input. This
vulnerability in code could lead to an arbitrary LDAP query execution.
severity: ERROR
metadata:
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
category: security
cwe:
- 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP
Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection/
- https://cwe.mitre.org/data/definitions/90
- https://cheatsheetseries.owasp.org/cheatsheets/LDAP_Injection_Prevention_Cheat_Sheet.html#safe-c-sharp-net-tba-example
subcategory:
- vuln
technology:
- .net
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- LDAP Injection
source: https://semgrep.dev/r/csharp.dotnet.security.audit.ldap-injection.ldap-injection
shortlink: https://sg.run/GJ9z
semgrep.dev:
rule:
r_id: 27692
rv_id: 1262612
rule_id: 2ZUv3R
version_id: l4TJR8G
url: https://semgrep.dev/playground/r/l4TJR8G/csharp.dotnet.security.audit.ldap-injection.ldap-injection
origin: community
languages:
- csharp
mode: taint
options:
taint_unify_mvars: true
pattern-sources:
- patterns:
- focus-metavariable: $INPUT
- pattern-inside: $T $M(...,$INPUT,...) {...}
pattern-sinks:
- patterns:
- pattern-either:
- pattern: $S.Filter = ... + $INPUT + ...
- pattern: $S.Filter = String.Format(...,$INPUT)
- pattern: $S.Filter = String.Concat(...,$INPUT)
pattern-sanitizers:
- pattern-either:
- pattern: Regex.Replace($INPUT, ...)
- pattern: $ENCODER.LdapFilterEncode($INPUT)
- pattern: $ENCODER.LdapDistinguishedNameEncode($INPUT)
- id: csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation
patterns:
- pattern-either:
- patterns:
- pattern: $LIFETIME = $FALSE
- pattern-inside: new TokenValidationParameters {...}
- patterns:
- pattern: |
(TokenValidationParameters $OPTS). ... .$LIFETIME = $FALSE
- metavariable-regex:
metavariable: $LIFETIME
regex: (RequireExpirationTime|ValidateLifetime)
- metavariable-regex:
metavariable: $FALSE
regex: (false)
- focus-metavariable: $FALSE
fix: |
true
message: The TokenValidationParameters.$LIFETIME is set to $FALSE, this means the
JWT tokens lifetime is not validated. This can lead to an JWT token being used
after it has expired, which has security implications. It is recommended to validate
the JWT lifetime to ensure only valid tokens are used.
metadata:
category: security
technology:
- csharp
owasp:
- A02:2017 - Broken Authentication
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe:
- 'CWE-613: Insufficient Session Expiration'
references:
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/
- https://cwe.mitre.org/data/definitions/613.html
- https://docs.microsoft.com/en-us/dotnet/api/microsoft.identitymodel.tokens.tokenvalidationparameters?view=azure-dotnet
subcategory:
- audit
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation
shortlink: https://sg.run/KA0d
semgrep.dev:
rule:
r_id: 28955
rv_id: 1262628
rule_id: bwU5kK
version_id: w8TRolJ
url: https://semgrep.dev/playground/r/w8TRolJ/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation
origin: community
languages:
- csharp
severity: WARNING
- id: java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml
patterns:
- pattern-inside: |
management:
...
endpoints:
...
web:
...
exposure:
...
- pattern: |
include: "*"
message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints
such as /actuator/env, /actuator/logfile, /actuator/heapdump and others. Unless
you have Spring Security enabled or another means to protect these endpoints,
this functionality is available without authentication, causing a severe security
risk.
severity: WARNING
languages:
- yaml
metadata:
cwe:
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints
- https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785
- https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators
category: security
technology:
- spring
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml
shortlink: https://sg.run/1Bzw
semgrep.dev:
rule:
r_id: 29422
rv_id: 1263076
rule_id: eqUerQ
version_id: w8TRo5n
url: https://semgrep.dev/playground/r/w8TRo5n/java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml
origin: community
- id: python.django.security.injection.command.subprocess-injection.subprocess-injection
languages:
- python
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- patterns:
- pattern-inside: |
def $FUNC(..., $REQUEST, ...):
...
- focus-metavariable: $REQUEST
- metavariable-pattern:
metavariable: $REQUEST
patterns:
- pattern: request
- pattern-not-inside: request.build_absolute_uri
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: subprocess.$FUNC(...)
- pattern-not: subprocess.$FUNC("...", ...)
- pattern-not: subprocess.$FUNC(["...", ...], ...)
- pattern-not-inside: |
$CMD = ["...", ...]
...
subprocess.$FUNC($CMD, ...)
- patterns:
- pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...)
- metavariable-regex:
metavariable: $SHELL
regex: ^(sh|bash|ksh|csh|tcsh|zsh)$
- patterns:
- pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...)
- metavariable-regex:
metavariable: $INTERPRETER
regex: ^(python|python\d)$
pattern-sanitizers:
- patterns:
- pattern: $DICT[$KEY]
- focus-metavariable: $KEY
severity: ERROR
message: Detected user input entering a `subprocess` call unsafely. This could result
in a command injection vulnerability. An attacker could use this vulnerability
to execute arbitrary commands on the host, which allows them to download malware,
scan sensitive data, or run any command they wish on the server. Do not let users
choose the command to run. In general, prefer to use Python API versions of system
commands. If you must use subprocess, use a dictionary to allowlist a set of commands.
metadata:
category: security
technology:
- flask
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
confidence: HIGH
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.django.security.injection.command.subprocess-injection.subprocess-injection
shortlink: https://sg.run/49BE
semgrep.dev:
rule:
r_id: 31144
rv_id: 1263388
rule_id: EwUepx
version_id: 7ZTE3qK
url: https://semgrep.dev/playground/r/7ZTE3qK/python.django.security.injection.command.subprocess-injection.subprocess-injection
origin: community
- id: python.django.security.injection.csv-writer-injection.csv-writer-injection
languages:
- python
message: Detected user input into a generated CSV file using the built-in `csv`
module. If user data is used to generate the data in this file, it is possible
that an attacker could inject a formula when the CSV is imported into a spreadsheet
application that runs an attacker script, which could steal data from the importing
user or, at worst, install malware on the user's computer. `defusedcsv` is a drop-in
replacement with the same API that will attempt to mitigate formula injection
attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs.
metadata:
category: security
confidence: MEDIUM
cwe:
- 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://github.com/raphaelm/defusedcsv
- https://owasp.org/www-community/attacks/CSV_Injection
- https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities
technology:
- django
- python
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/python.django.security.injection.csv-writer-injection.csv-writer-injection
shortlink: https://sg.run/Pw9q
semgrep.dev:
rule:
r_id: 31145
rv_id: 1263389
rule_id: 7KUK1y
version_id: LjTkgD9
url: https://semgrep.dev/playground/r/LjTkgD9/python.django.security.injection.csv-writer-injection.csv-writer-injection
origin: community
mode: taint
pattern-sinks:
- patterns:
- pattern-inside: |
$WRITER = csv.writer(...)
...
$WRITER.$WRITE(...)
- pattern: $WRITER.$WRITE(...)
- metavariable-regex:
metavariable: $WRITE
regex: ^(writerow|writerows|writeheader)$
pattern-sources:
- patterns:
- pattern-inside: |
def $FUNC(..., $REQUEST, ...):
...
- focus-metavariable: $REQUEST
- metavariable-pattern:
metavariable: $REQUEST
patterns:
- pattern: request
- pattern-not-inside: request.build_absolute_uri
severity: ERROR
- id: python.flask.security.injection.csv-writer-injection.csv-writer-injection
languages:
- python
message: Detected user input into a generated CSV file using the built-in `csv`
module. If user data is used to generate the data in this file, it is possible
that an attacker could inject a formula when the CSV is imported into a spreadsheet
application that runs an attacker script, which could steal data from the importing
user or, at worst, install malware on the user's computer. `defusedcsv` is a drop-in
replacement with the same API that will attempt to mitigate formula injection
attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs.
metadata:
category: security
confidence: MEDIUM
cwe:
- 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://github.com/raphaelm/defusedcsv
- https://owasp.org/www-community/attacks/CSV_Injection
- https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities
technology:
- python
- flask
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/python.flask.security.injection.csv-writer-injection.csv-writer-injection
shortlink: https://sg.run/JzqQ
semgrep.dev:
rule:
r_id: 31146
rv_id: 1263428
rule_id: L1UR2K
version_id: jQTn50Y
url: https://semgrep.dev/playground/r/jQTn50Y/python.flask.security.injection.csv-writer-injection.csv-writer-injection
origin: community
mode: taint
pattern-sinks:
- patterns:
- pattern-inside: |
$WRITER = csv.writer(...)
...
$WRITER.$WRITE(...)
- pattern: $WRITER.$WRITE(...)
- metavariable-regex:
metavariable: $WRITE
regex: ^(writerow|writerows|writeheader)$
pattern-sources:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: flask.request.form.get(...)
- pattern: flask.request.form[...]
- pattern: flask.request.args.get(...)
- pattern: flask.request.args[...]
- pattern: flask.request.values.get(...)
- pattern: flask.request.values[...]
- pattern: flask.request.cookies.get(...)
- pattern: flask.request.cookies[...]
- pattern: flask.request.stream
- pattern: flask.request.headers.get(...)
- pattern: flask.request.headers[...]
- pattern: flask.request.data
- pattern: flask.request.full_path
- pattern: flask.request.url
- pattern: flask.request.json
- pattern: flask.request.get_json()
- pattern: flask.request.view_args.get(...)
- pattern: flask.request.view_args[...]
- patterns:
- pattern-inside: |
@$APP.route($ROUTE, ...)
def $FUNC(..., $ROUTEVAR, ...):
...
- focus-metavariable: $ROUTEVAR
severity: ERROR
- id: python.flask.security.injection.subprocess-injection.subprocess-injection
languages:
- python
mode: taint
options:
symbolic_propagation: true
pattern-sources:
- pattern-either:
- patterns:
- pattern-either:
- pattern: flask.request.form.get(...)
- pattern: flask.request.form[...]
- pattern: flask.request.args.get(...)
- pattern: flask.request.args[...]
- pattern: flask.request.values.get(...)
- pattern: flask.request.values[...]
- pattern: flask.request.cookies.get(...)
- pattern: flask.request.cookies[...]
- pattern: flask.request.stream
- pattern: flask.request.headers.get(...)
- pattern: flask.request.headers[...]
- pattern: flask.request.data
- pattern: flask.request.full_path
- pattern: flask.request.url
- pattern: flask.request.json
- pattern: flask.request.get_json()
- pattern: flask.request.view_args.get(...)
- pattern: flask.request.view_args[...]
- patterns:
- pattern-inside: |
@$APP.route($ROUTE, ...)
def $FUNC(..., $ROUTEVAR, ...):
...
- focus-metavariable: $ROUTEVAR
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: subprocess.$FUNC(...)
- pattern-not: subprocess.$FUNC("...", ...)
- pattern-not: subprocess.$FUNC(["...", ...], ...)
- pattern-not-inside: |
$CMD = ["...", ...]
...
subprocess.$FUNC($CMD, ...)
- patterns:
- pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...)
- metavariable-regex:
metavariable: $SHELL
regex: ^(sh|bash|ksh|csh|tcsh|zsh)$
- patterns:
- pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...)
- metavariable-regex:
metavariable: $INTERPRETER
regex: ^(python|python\d)$
pattern-sanitizers:
- patterns:
- pattern: $DICT[$KEY]
- focus-metavariable: $KEY
severity: ERROR
message: Detected user input entering a `subprocess` call unsafely. This could result
in a command injection vulnerability. An attacker could use this vulnerability
to execute arbitrary commands on the host, which allows them to download malware,
scan sensitive data, or run any command they wish on the server. Do not let users
choose the command to run. In general, prefer to use Python API versions of system
commands. If you must use subprocess, use a dictionary to allowlist a set of commands.
metadata:
category: security
technology:
- flask
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
references:
- https://semgrep.dev/docs/cheat-sheets/python-command-injection/
confidence: HIGH
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/python.flask.security.injection.subprocess-injection.subprocess-injection
shortlink: https://sg.run/5gW3
semgrep.dev:
rule:
r_id: 31147
rv_id: 1263433
rule_id: 8GU3qp
version_id: bZT53gQ
url: https://semgrep.dev/playground/r/bZT53gQ/python.flask.security.injection.subprocess-injection.subprocess-injection
origin: community
- id: yaml.github-actions.security.github-script-injection.github-script-injection
languages:
- yaml
message: 'Using variable interpolation `${{...}}` with `github` context data in
a `actions/github-script`''s `script:` step could allow an attacker to inject
their own code into the runner. This would allow them to steal secrets and code.
`github` context data can have arbitrary user input and should be treated as untrusted.
Instead, use an intermediate environment variable with `env:` to store the data
and use the environment variable in the `run:` script. Be sure to use double-quotes
the environment variable, like this: "$ENVVAR".'
metadata:
category: security
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections
- https://securitylab.github.com/research/github-actions-untrusted-input/
- https://github.com/actions/github-script
technology:
- github-actions
cwe2022-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/yaml.github-actions.security.github-script-injection.github-script-injection
shortlink: https://sg.run/g1G0
semgrep.dev:
rule:
r_id: 31441
rv_id: 1423394
rule_id: OrUQvK
version_id: 5PT7Zyw
url: https://semgrep.dev/playground/r/5PT7Zyw/yaml.github-actions.security.github-script-injection.github-script-injection
origin: community
patterns:
- pattern-inside: 'steps: [...]'
- pattern-inside: |
uses: $ACTION
...
- pattern-inside: |
with:
...
script: ...
...
- pattern: 'script: $SHELL'
- metavariable-regex:
metavariable: $ACTION
regex: actions/github-script@.*
- metavariable-pattern:
language: generic
metavariable: $SHELL
patterns:
- pattern-either:
- pattern: ${{ ... github.event.issue.title ... }}
- pattern: ${{ ... github.event.issue.body ... }}
- pattern: ${{ ... github.event.pull_request.title ... }}
- pattern: ${{ ... github.event.pull_request.body ... }}
- pattern: ${{ ... github.event.comment.body ... }}
- pattern: ${{ ... github.event.review.body ... }}
- pattern: ${{ ... github.event.review_comment.body ... }}
- pattern: ${{ ... github.event.pages ... .page_name ... }}
- pattern: ${{ ... github.event.head_commit.message ... }}
- pattern: ${{ ... github.event.head_commit.author.email ... }}
- pattern: ${{ ... github.event.head_commit.author.name ... }}
- pattern: ${{ ... github.event.commits ... .author.email ... }}
- pattern: ${{ ... github.event.commits ... .author.name ... }}
- pattern: ${{ ... github.event.commits ... .message ... }}
- pattern: ${{ ... github.event.pull_request.head.ref ... }}
- pattern: ${{ ... github.event.pull_request.head.label ... }}
- pattern: ${{ ... github.event.pull_request.head.repo.default_branch ...
}}
- pattern: ${{ ... github.ref ... }}
- pattern: ${{ ... github.base_ref ... }}
- pattern: ${{ ... github.head_ref ... }}
- pattern: ${{ ... github.ref_name ... }}
- pattern: ${{ ... github.workflow ... }}
- pattern: ${{ ... github.event.inputs ... }}
- pattern: ${{ ... github.event.discussion.title ... }}
- pattern: ${{ ... github.event.discussion.body ... }}
- pattern: ${{ ... github.event.workflow_run.head_branch ... }}
- pattern: ${{ ... github.event.workflow_run.head_commit.message ... }}
- pattern: ${{ ... github.event.milestone.title ... }}
- pattern: ${{ ... github.event.milestone.description ... }}
- pattern: ${{ ... github.event.project_card.note ... }}
- pattern: ${{ ... github.event.project.name ... }}
- pattern: ${{ ... github.event.project_column.name ... }}
- pattern: ${{ ... github.event.release.name ... }}
- pattern: ${{ ... github.event.release.body ... }}
- pattern: ${{ ... github.event.deployment.ref ... }}
- pattern: ${{ ... inputs ... }}
- pattern-not: ${{ ... github.event.issue.title && ... }}
- pattern-not: ${{ ... github.event.issue.body && ... }}
- pattern-not: ${{ ... github.event.pull_request.title && ... }}
- pattern-not: ${{ ... github.event.pull_request.body && ... }}
- pattern-not: ${{ ... github.event.comment.body && ... }}
- pattern-not: ${{ ... github.event.review.body && ... }}
- pattern-not: ${{ ... github.event.review_comment.body && ... }}
- pattern-not: ${{ ... github.event.pages ... .page_name && ... }}
- pattern-not: ${{ ... github.event.head_commit.message && ... }}
- pattern-not: ${{ ... github.event.head_commit.author.email && ... }}
- pattern-not: ${{ ... github.event.head_commit.author.name && ... }}
- pattern-not: ${{ ... github.event.commits ... .author.email && ... }}
- pattern-not: ${{ ... github.event.commits ... .author.name && ... }}
- pattern-not: ${{ ... github.event.commits ... .message && ... }}
- pattern-not: ${{ ... github.event.pull_request.head.ref && ... }}
- pattern-not: ${{ ... github.event.pull_request.head.label && ... }}
- pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch &&
... }}
- pattern-not: ${{ ... github.ref && ... }}
- pattern-not: ${{ ... github.base_ref && ... }}
- pattern-not: ${{ ... github.head_ref && ... }}
- pattern-not: ${{ ... github.ref_name && ... }}
- pattern-not: ${{ ... github.workflow && ... }}
- pattern-not: ${{ ... github.event.inputs && ... }}
- pattern-not: ${{ ... github.event.discussion.title && ... }}
- pattern-not: ${{ ... github.event.discussion.body && ... }}
- pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }}
- pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ...
}}
- pattern-not: ${{ ... github.event.milestone.title && ... }}
- pattern-not: ${{ ... github.event.milestone.description && ... }}
- pattern-not: ${{ ... github.event.project_card.note && ... }}
- pattern-not: ${{ ... github.event.project.name && ... }}
- pattern-not: ${{ ... github.event.project_column.name && ... }}
- pattern-not: ${{ ... github.event.release.name && ... }}
- pattern-not: ${{ ... github.event.release.body && ... }}
- pattern-not: ${{ ... github.event.deployment.ref && ... }}
severity: ERROR
- id: php.lang.security.injection.echoed-request.echoed-request
mode: taint
message: '`Echo`ing user input risks cross-site scripting vulnerability. You should
use `htmlentities()` when showing data to users.'
languages:
- php
severity: ERROR
pattern-sources:
- pattern: $_REQUEST
- pattern: $_GET
- pattern: $_POST
pattern-sinks:
- pattern: echo $...VARS;
pattern-sanitizers:
- pattern: htmlentities(...)
- pattern: htmlspecialchars(...)
- pattern: strip_tags(...)
- pattern: isset(...)
- pattern: empty(...)
- pattern: esc_html(...)
- pattern: esc_attr(...)
- pattern: wp_kses(...)
- pattern: e(...)
- pattern: twig_escape_filter(...)
- pattern: xss_clean(...)
- pattern: html_escape(...)
- pattern: Html::escape(...)
- pattern: Xss::filter(...)
- pattern: escapeHtml(...)
- pattern: escapeHtml(...)
- pattern: escapeHtmlAttr(...)
fix: echo htmlentities($...VARS);
metadata:
technology:
- php
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
references:
- https://www.php.net/manual/en/function.htmlentities.php
- https://www.php.net/manual/en/reserved.variables.request.php
- https://www.php.net/manual/en/reserved.variables.post.php
- https://www.php.net/manual/en/reserved.variables.get.php
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/php.lang.security.injection.echoed-request.echoed-request
shortlink: https://sg.run/Bqqb
semgrep.dev:
rule:
r_id: 31707
rv_id: 1263283
rule_id: BYUyyg
version_id: d6TyxE9
url: https://semgrep.dev/playground/r/d6TyxE9/php.lang.security.injection.echoed-request.echoed-request
origin: community
- id: python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication
message: 'An encryption mode of operation is being used without proper message authentication.
This can potentially result in the encrypted content to be decrypted by an attacker.
Consider instead use an AEAD mode of operation like GCM. '
languages:
- python
severity: ERROR
metadata:
category: security
technology:
- cryptography
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication
shortlink: https://sg.run/N9JL
semgrep.dev:
rule:
r_id: 31871
rv_id: 1263357
rule_id: lBUpNZ
version_id: BjTkZj5
url: https://semgrep.dev/playground/r/BjTkZj5/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication
origin: community
patterns:
- pattern-either:
- patterns:
- pattern: |
Cipher(..., $HAZMAT_MODE(...),...)
- pattern-not-inside: |
Cipher(..., $HAZMAT_MODE(...),...)
...
HMAC(...)
- pattern-not-inside: |
Cipher(..., $HAZMAT_MODE(...),...)
...
hmac.HMAC(...)
- metavariable-pattern:
metavariable: $HAZMAT_MODE
patterns:
- pattern-either:
- pattern: modes.CTR
- pattern: modes.CBC
- pattern: modes.CFB
- pattern: modes.OFB
- id: python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication
message: 'An encryption mode of operation is being used without proper message authentication.
This can potentially result in the encrypted content to be decrypted by an attacker.
Consider instead use an AEAD mode of operation like GCM. '
languages:
- python
severity: ERROR
metadata:
category: security
technology:
- cryptography
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication
shortlink: https://sg.run/k1K1
semgrep.dev:
rule:
r_id: 31872
rv_id: 1263556
rule_id: YGUw8w
version_id: GxTkeyz
url: https://semgrep.dev/playground/r/GxTkeyz/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication
origin: community
patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: |
AES.new(..., $PYCRYPTODOME_MODE)
- pattern-not-inside: |
AES.new(..., $PYCRYPTODOME_MODE)
...
HMAC.new
- metavariable-pattern:
metavariable: $PYCRYPTODOME_MODE
patterns:
- pattern-either:
- pattern: AES.MODE_CBC
- pattern: AES.MODE_CTR
- pattern: AES.MODE_CFB
- pattern: AES.MODE_OFB
- id: java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml
patterns:
- pattern-inside: |
management:
...
endpoints:
...
web:
...
exposure:
...
include:
...
- pattern: |
include: [..., $ACTUATOR, ...]
- metavariable-comparison:
metavariable: $ACTUATOR
comparison: not str($ACTUATOR) in ["health","*"]
message: Spring Boot Actuator "$ACTUATOR" is enabled. Depending on the actuator,
this can pose a significant security risk. Please double-check if the actuator
is needed and properly secured.
severity: WARNING
languages:
- yaml
metadata:
cwe:
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints
- https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785
- https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators
category: security
technology:
- spring
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml
shortlink: https://sg.run/JzKQ
semgrep.dev:
rule:
r_id: 32290
rv_id: 1263078
rule_id: kxUWpX
version_id: O9TpxBp
url: https://semgrep.dev/playground/r/O9TpxBp/java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml
origin: community
- id: java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled
patterns:
- pattern: management.endpoints.web.exposure.include=$...ACTUATORS
- metavariable-comparison:
metavariable: $...ACTUATORS
comparison: not str($...ACTUATORS) in ["health","*"]
message: Spring Boot Actuators "$...ACTUATORS" are enabled. Depending on the actuators,
this can pose a significant security risk. Please double-check if the actuators
are needed and properly secured.
severity: WARNING
languages:
- generic
options:
generic_ellipsis_max_span: 0
metadata:
cwe:
- 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints
- https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785
- https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators
category: security
technology:
- spring
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled
shortlink: https://sg.run/5g23
semgrep.dev:
rule:
r_id: 32291
rv_id: 1263079
rule_id: wdUWrZ
version_id: e1Tyjqe
url: https://semgrep.dev/playground/r/e1Tyjqe/java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled
origin: community
- id: terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging
patterns:
- pattern: |
resource "google_storage_bucket" $ANYTHING {
...
}
- pattern-not-inside: "resource \"google_storage_bucket\" $ANYTHING {\n ...\n logging
{\n log_bucket = ...\n } \n ...\n}\n"
message: Ensure bucket logs access.
languages:
- hcl
severity: WARNING
metadata:
owasp:
- A10:2017 - Insufficient Logging & Monitoring
- A09:2021 - Security Logging and Monitoring Failures
- A09:2025 - Security Logging & Alerting Failures
cwe:
- 'CWE-778: Insufficient Logging'
technology:
- terraform
- gcp
category: security
references:
- https://docs.bridgecrew.io/docs/google-cloud-policy-index
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insufficient Logging
source: https://semgrep.dev/r/terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging
shortlink: https://sg.run/5g5D
semgrep.dev:
rule:
r_id: 32303
rv_id: 1263813
rule_id: gxUrdg
version_id: JdTzxRN
url: https://semgrep.dev/playground/r/JdTzxRN/terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging
origin: community
- id: python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4
message: ARC4 (Alleged RC4) is a stream cipher with serious weaknesses in its initial
stream output. Its use is strongly discouraged. ARC4 does not use mode constructions.
Use a strong symmetric cipher such as EAS instead. With the `cryptography` package
it is recommended to use the `Fernet` which is a secure implementation of AES
in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class
from the hazmat primitives but use the AES algorithm instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B304
references:
- https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers
category: security
technology:
- cryptography
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
functional-categories:
- crypto::search::symmetric-algorithm::cryptography
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4
shortlink: https://sg.run/xoZL
semgrep.dev:
rule:
r_id: 33630
rv_id: 1263348
rule_id: KxU8gK
version_id: QkTGq3Q
url: https://semgrep.dev/playground/r/QkTGq3Q/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4
origin: community
severity: WARNING
languages:
- python
patterns:
- pattern: cryptography.hazmat.primitives.ciphers.algorithms.$ARC4($KEY)
- pattern-inside: cryptography.hazmat.primitives.ciphers.Cipher(...)
- metavariable-regex:
metavariable: $ARC4
regex: ^(ARC4)$
- focus-metavariable: $ARC4
fix: AES
- id: python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish
message: Blowfish is a block cipher developed by Bruce Schneier. It is known to
be susceptible to attacks when using weak keys. The author has recommended that
users of Blowfish move to newer algorithms such as AES. With the `cryptography`
package it is recommended to use `Fernet` which is a secure implementation of
AES in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class
from the hazmat primitives but use the AES algorithm instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B304
references:
- https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers
- https://tools.ietf.org/html/rfc5469
category: security
technology:
- cryptography
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
functional-categories:
- crypto::search::symmetric-algorithm::cryptography
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish
shortlink: https://sg.run/OdzL
semgrep.dev:
rule:
r_id: 33631
rv_id: 1263349
rule_id: qNULvO
version_id: 3ZT4XK7
url: https://semgrep.dev/playground/r/3ZT4XK7/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish
origin: community
severity: WARNING
languages:
- python
patterns:
- pattern: cryptography.hazmat.primitives.ciphers.algorithms.$BLOWFISH($KEY)
- metavariable-regex:
metavariable: $BLOWFISH
regex: ^(Blowfish)$
- focus-metavariable: $BLOWFISH
fix: AES
- id: python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
resistant and is therefore not suitable as a cryptographic signature. Use SHA256
or SHA3 instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B303
references:
- https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#md5
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
- http://2012.sharcs.org/slides/stevens.pdf
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
category: security
technology:
- cryptography
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
functional-categories:
- crypto::search::symmetric-algorithm::cryptography
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
shortlink: https://sg.run/eY88
semgrep.dev:
rule:
r_id: 33632
rv_id: 1263352
rule_id: lBUopp
version_id: JdTzxww
url: https://semgrep.dev/playground/r/JdTzxww/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
origin: community
severity: WARNING
languages:
- python
patterns:
- pattern: cryptography.hazmat.primitives.hashes.$MD5()
- metavariable-regex:
metavariable: $MD5
regex: ^(MD5)$
- focus-metavariable: $MD5
fix: SHA256
- id: python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
patterns:
- pattern: hashlib.md5(...)
- pattern-not: hashlib.md5(..., usedforsecurity=False, ...)
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
resistant and is therefore not suitable as a cryptographic signature. Use SHA256
or SHA3 instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B303
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.2 Insecure Custom Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
references:
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
- http://2012.sharcs.org/slides/stevens.pdf
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
category: security
technology:
- python
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
shortlink: https://sg.run/vYrY
semgrep.dev:
rule:
r_id: 33633
rv_id: 1263536
rule_id: PeU2e2
version_id: kbTzGE1
url: https://semgrep.dev/playground/r/kbTzGE1/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5
origin: community
severity: WARNING
languages:
- python
- id: python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish
message: Detected Blowfish cipher algorithm which is considered insecure. This algorithm
is not cryptographically secure and can be reversed easily. Use secure stream
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
with a block size of 128 bits. When using a block cipher, use a modern mode of
operation that also provides authentication, such as GCM.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B304
references:
- https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption
- https://www.pycryptodome.org/src/cipher/cipher
category: security
technology:
- pycryptodome
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
functional-categories:
- crypto::search::symmetric-algorithm::pycryptodome
- crypto::search::symmetric-algorithm::pycryptodomex
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish
shortlink: https://sg.run/dlOE
semgrep.dev:
rule:
r_id: 33634
rv_id: 1263545
rule_id: JDUGnK
version_id: ExTExln
url: https://semgrep.dev/playground/r/ExTExln/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish
origin: community
options:
symbolic_propagation: true
severity: WARNING
languages:
- python
pattern-either:
- pattern: Cryptodome.Cipher.Blowfish.new(...)
- pattern: Crypto.Cipher.Blowfish.new(...)
- id: python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des
message: Detected DES cipher or Triple DES algorithm which is considered insecure.
This algorithm is not cryptographically secure and can be reversed easily. Use
a secure symmetric cipher from the cryptodome package instead. Use secure stream
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
with a block size of 128 bits. When using a block cipher, use a modern mode of
operation that also provides authentication, such as GCM.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B304
references:
- https://cwe.mitre.org/data/definitions/326.html
- https://www.pycryptodome.org/src/cipher/cipher
category: security
technology:
- pycryptodome
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
functional-categories:
- crypto::search::symmetric-algorithm::pycryptodome
- crypto::search::symmetric-algorithm::pycryptodomex
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des
shortlink: https://sg.run/Z5bw
semgrep.dev:
rule:
r_id: 33635
rv_id: 1263546
rule_id: 5rUr73
version_id: 7ZTE3G7
url: https://semgrep.dev/playground/r/7ZTE3G7/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des
origin: community
options:
symbolic_propagation: true
severity: WARNING
languages:
- python
pattern-either:
- pattern: Cryptodome.Cipher.DES.new(...)
- pattern: Crypto.Cipher.DES.new(...)
- pattern: Cryptodome.Cipher.DES3.new(...)
- pattern: Crypto.Cipher.DES3.new(...)
- id: python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2
message: Detected RC2 cipher algorithm which is considered insecure. This algorithm
is not cryptographically secure and can be reversed easily. Use secure stream
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
with a block size of 128 bits. When using a block cipher, use a modern mode of
operation that also provides authentication, such as GCM.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B304
references:
- https://cwe.mitre.org/data/definitions/326.html
- https://www.pycryptodome.org/src/cipher/cipher
category: security
technology:
- pycryptodome
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
functional-categories:
- crypto::search::symmetric-algorithm::pycryptodome
- crypto::search::symmetric-algorithm::pycryptodomex
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2
shortlink: https://sg.run/nAbY
semgrep.dev:
rule:
r_id: 33636
rv_id: 1263547
rule_id: GdUYlW
version_id: LjTkgn6
url: https://semgrep.dev/playground/r/LjTkgn6/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2
origin: community
options:
symbolic_propagation: true
severity: WARNING
languages:
- python
pattern-either:
- pattern: Cryptodome.Cipher.ARC2.new(...)
- pattern: Crypto.Cipher.ARC2.new(...)
- id: python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4
message: Detected ARC4 cipher algorithm which is considered insecure. This algorithm
is not cryptographically secure and can be reversed easily. Use secure stream
ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES
with a block size of 128 bits. When using a block cipher, use a modern mode of
operation that also provides authentication, such as GCM.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
bandit-code: B304
references:
- https://cwe.mitre.org/data/definitions/326.html
- https://www.pycryptodome.org/src/cipher/cipher
category: security
technology:
- pycryptodome
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
functional-categories:
- crypto::search::symmetric-algorithm::pycryptodome
- crypto::search::symmetric-algorithm::pycryptodomex
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4
shortlink: https://sg.run/Eo6N
semgrep.dev:
rule:
r_id: 33637
rv_id: 1263548
rule_id: ReUnEB
version_id: 8KT5rXY
url: https://semgrep.dev/playground/r/8KT5rXY/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4
origin: community
severity: WARNING
languages:
- python
pattern-either:
- pattern: Cryptodome.Cipher.ARC4.new(...)
- pattern: Crypto.Cipher.ARC4.new(...)
- id: python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2
message: Detected MD2 hash algorithm which is considered insecure. MD2 is not collision
resistant and is therefore not suitable as a cryptographic signature. Use a modern
hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
- http://2012.sharcs.org/slides/stevens.pdf
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
category: security
technology:
- pycryptodome
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
functional-categories:
- crypto::search::hash-algorithm::pycryptodome
- crypto::search::hash-algorithm::pycryptodomex
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2
shortlink: https://sg.run/7JP2
semgrep.dev:
rule:
r_id: 33638
rv_id: 1263550
rule_id: AbU0Ex
version_id: QkTGqD8
url: https://semgrep.dev/playground/r/QkTGqD8/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2
origin: community
options:
symbolic_propagation: true
severity: WARNING
languages:
- python
pattern-either:
- pattern: Crypto.Hash.MD2.new(...)
- pattern: Cryptodome.Hash.MD2.new (...)
- id: python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4
message: Detected MD4 hash algorithm which is considered insecure. MD4 is not collision
resistant and is therefore not suitable as a cryptographic signature. Use a modern
hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
- http://2012.sharcs.org/slides/stevens.pdf
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
category: security
technology:
- pycryptodome
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
functional-categories:
- crypto::search::hash-algorithm::pycryptodome
- crypto::search::hash-algorithm::pycryptodomex
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4
shortlink: https://sg.run/Lve6
semgrep.dev:
rule:
r_id: 33639
rv_id: 1263551
rule_id: BYUJy4
version_id: 3ZT4Xnp
url: https://semgrep.dev/playground/r/3ZT4Xnp/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4
origin: community
options:
symbolic_propagation: true
severity: WARNING
languages:
- python
pattern-either:
- pattern: Crypto.Hash.MD4.new(...)
- pattern: Cryptodome.Hash.MD4.new (...)
- id: python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
resistant and is therefore not suitable as a cryptographic signature. Use a modern
hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead.
metadata:
source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms
- https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability
- http://2012.sharcs.org/slides/stevens.pdf
- https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html
category: security
technology:
- pycryptodome
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
functional-categories:
- crypto::search::hash-algorithm::pycryptodome
- crypto::search::hash-algorithm::pycryptodomex
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5
shortlink: https://sg.run/85JN
semgrep.dev:
rule:
r_id: 33640
rv_id: 1263552
rule_id: DbUXwo
version_id: 44TEjpk
url: https://semgrep.dev/playground/r/44TEjpk/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5
origin: community
options:
symbolic_propagation: true
severity: WARNING
languages:
- python
pattern-either:
- pattern: Crypto.Hash.MD5.new(...)
- pattern: Cryptodome.Hash.MD5.new (...)
- id: terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1
patterns:
- pattern: resource
- pattern-inside: |
resource "google_dns_managed_zone" "..." {
...
dnssec_config {
...
default_key_specs {
...
algorithm = "rsasha1"
key_type = "zoneSigning"
...
}
...
}
...
}
- pattern-inside: |
resource "google_dns_managed_zone" "..." {
...
dnssec_config {
...
default_key_specs {
...
algorithm = "rsasha1"
key_type = "keySigning"
...
}
...
}
...
}
message: "Ensure that RSASHA1 is not used for the zone-signing and key-signing keys
in Cloud DNS DNSSEC\t"
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
category: security
technology:
- terraform
- gcp
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1
shortlink: https://sg.run/bKKW
semgrep.dev:
rule:
r_id: 33670
rv_id: 1263837
rule_id: 7KUZZb
version_id: bZT53oD
url: https://semgrep.dev/playground/r/bZT53oD/terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl
patterns:
- pattern: resource
- pattern-inside: |
resource "google_sql_database_instance" "..." {
...
}
- pattern-not-inside: |
resource "google_sql_database_instance" "..." {
...
ip_configuration {
...
require_ssl = true
...
}
...
}
- pattern-not-inside: |
resource "google_sql_database_instance" "..." {
...
ip_configuration {
...
ssl_mode = ...
...
}
...
}
message: Ensure all Cloud SQL database instance requires all incoming connections
to use SSL
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
category: security
technology:
- terraform
- gcp
references:
- https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl
shortlink: https://sg.run/W4Yg
semgrep.dev:
rule:
r_id: 33709
rv_id: 1263873
rule_id: v8Uod5
version_id: pZT033e
url: https://semgrep.dev/playground/r/pZT033e/terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database
patterns:
- pattern: resource
- pattern-either:
- pattern-inside: |
resource "google_sql_database_instance" "..." {
...
ip_configuration {
...
authorized_networks {
...
value = "0.0.0.0/0"
...
}
...
}
...
}
- pattern-inside: |
resource "google_sql_database_instance" "..." {
...
ip_configuration {
...
dynamic "authorized_networks" {
...
content {
...
value = "0.0.0.0/0"
...
}
...
}
...
}
...
}
message: Ensure that Cloud SQL database Instances are not open to the world
metadata:
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-1220: Insufficient Granularity of Access Control'
category: security
technology:
- terraform
- gcp
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database
shortlink: https://sg.run/0Xv5
semgrep.dev:
rule:
r_id: 33710
rv_id: 1263876
rule_id: d8U7Ll
version_id: jQTn559
url: https://semgrep.dev/playground/r/jQTn559/terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database
origin: community
languages:
- hcl
severity: WARNING
- id: csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding
message: You are using the outdated PKCS#1 v1.5 encryption padding for your RSA
key. Use the OAEP padding instead.
severity: WARNING
metadata:
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
category: security
cwe:
- 'CWE-780: Use of RSA Algorithm without OAEP'
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsapkcs1keyexchangeformatter
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsaoaepkeyexchangeformatter
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsapkcs1keyexchangedeformatter
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsaoaepkeyexchangedeformatter
subcategory:
- vuln
technology:
- .net
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding
shortlink: https://sg.run/GoJ1
semgrep.dev:
rule:
r_id: 35492
rv_id: 1262625
rule_id: QrU2G5
version_id: bZT53zb
url: https://semgrep.dev/playground/r/bZT53zb/csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding
origin: community
languages:
- csharp
pattern-either:
- pattern: (RSAPKCS1KeyExchangeFormatter $FORMATER).CreateKeyExchange(...);
- pattern: (RSAPKCS1KeyExchangeDeformatter $DEFORMATER).DecryptKeyExchange(...);
- id: php.lang.security.redirect-to-request-uri.redirect-to-request-uri
patterns:
- pattern-either:
- pattern: |
header('$LOCATION' . $_SERVER['REQUEST_URI']);
- pattern: |
header('$LOCATION' . $_SERVER['REQUEST_URI'] . $MORE);
- metavariable-regex:
metavariable: $LOCATION
regex: ^(?i)location:\s*$
message: Redirecting to the current request URL may redirect to another domain,
if the current path starts with two slashes. E.g. in https://www.example.com//attacker.com,
the value of REQUEST_URI is //attacker.com, and redirecting to it will redirect
to that domain.
metadata:
references:
- https://www.php.net/manual/en/reserved.variables.server.php
- https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html
category: security
technology:
- php
owasp:
- A05:2017 - Broken Access Control
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')'
likelihood: MEDIUM
impact: LOW
confidence: MEDIUM
subcategory:
- vuln
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Open Redirect
source: https://semgrep.dev/r/php.lang.security.redirect-to-request-uri.redirect-to-request-uri
shortlink: https://sg.run/RWl2
semgrep.dev:
rule:
r_id: 35493
rv_id: 1263299
rule_id: 3qUb4n
version_id: A8Tgdvq
url: https://semgrep.dev/playground/r/A8Tgdvq/php.lang.security.redirect-to-request-uri.redirect-to-request-uri
origin: community
languages:
- php
severity: WARNING
- id: yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout
languages:
- yaml
message: This GitHub Actions workflow file uses `workflow_run` and checks out code
from the incoming pull request. When using `workflow_run`, the Action runs in
the context of the target repository, which includes access to all repository
secrets. Normally, this is safe because the Action only runs code from the target
repository, not the incoming PR. However, by checking out the incoming PR code,
you're now using the incoming code for the rest of the action. You may be inadvertently
executing arbitrary code from the incoming PR with access to repository secrets,
which would let an attacker steal repository secrets. This normally happens by
running build scripts (e.g., `npm build` and `make`) or dependency installation
scripts (e.g., `python setup.py install`). Audit your workflow file to make sure
no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
for additional mitigations.
metadata:
category: security
owasp: A01:2017 - Injection
cwe: 'CWE-913: Improper Control of Dynamically-Managed Code Resources'
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
subcategory:
- vuln
references:
- https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
- https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md
- https://www.legitsecurity.com/blog/github-privilege-escalation-vulnerability
technology:
- github-actions
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout
shortlink: https://sg.run/A0p6
semgrep.dev:
rule:
r_id: 35494
rv_id: 947046
rule_id: 4bU8E4
version_id: kbTYRwl
url: https://semgrep.dev/playground/r/kbTYRwl/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout
origin: community
patterns:
- pattern-inside: |
on:
...
workflow_run: ...
...
...
- pattern-inside: |
jobs:
...
$JOBNAME:
...
steps:
...
- pattern: |
...
uses: "$ACTION"
with:
...
ref: $EXPR
- metavariable-regex:
metavariable: $ACTION
regex: actions/checkout@.*
- metavariable-pattern:
language: generic
metavariable: $EXPR
patterns:
- pattern: ${{ github.event.workflow_run ... }}
severity: WARNING
- id: csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm
message: Usage of deprecated cipher algorithm detected. Use Aes or ChaCha20Poly1305
instead.
severity: ERROR
metadata:
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
category: security
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.des?view=net-6.0#remarks
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rc2?view=net-6.0#remarks
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aes?view=net-6.0
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0
subcategory:
- vuln
technology:
- .net
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm
shortlink: https://sg.run/k8Qo
semgrep.dev:
rule:
r_id: 36772
rv_id: 1262622
rule_id: WAUJr0
version_id: 9lT4bRK
url: https://semgrep.dev/playground/r/9lT4bRK/csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm
origin: community
languages:
- csharp
patterns:
- pattern: $KEYTYPE.Create(...);
- metavariable-pattern:
metavariable: $KEYTYPE
pattern-either:
- pattern: DES
- pattern: RC2
- id: csharp.dotnet.security.use_ecb_mode.use_ecb_mode
message: Usage of the insecure ECB mode detected. You should use an authenticated
encryption mode instead, which is implemented by the classes AesGcm or ChaCha20Poly1305.
severity: WARNING
metadata:
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
category: security
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0
- https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.ciphermode?view=net-6.0
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes
subcategory:
- vuln
technology:
- .net
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/csharp.dotnet.security.use_ecb_mode.use_ecb_mode
shortlink: https://sg.run/wj9n
semgrep.dev:
rule:
r_id: 36773
rv_id: 1262623
rule_id: 0oUqWP
version_id: yeTxpPw
url: https://semgrep.dev/playground/r/yeTxpPw/csharp.dotnet.security.use_ecb_mode.use_ecb_mode
origin: community
languages:
- csharp
patterns:
- pattern-either:
- pattern: ($KEYTYPE $KEY).EncryptEcb(...);
- pattern: ($KEYTYPE $KEY).DecryptEcb(...);
- pattern: ($KEYTYPE $KEY).Mode = CipherMode.ECB;
- metavariable-pattern:
metavariable: $KEYTYPE
pattern-either:
- pattern: SymmetricAlgorithm
- pattern: Aes
- pattern: Rijndael
- pattern: DES
- pattern: TripleDES
- pattern: RC2
- id: csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration
message: You are using an insecure random number generator (RNG) to create a cryptographic
key. System.Random must never be used for cryptographic purposes. Use System.Security.Cryptography.RandomNumberGenerator
instead.
severity: ERROR
metadata:
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
category: security
cwe:
- 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)'
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://learn.microsoft.com/en-us/dotnet/api/system.random?view=net-6.0#remarks
- https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.randomnumbergenerator?view=net-6.0
- https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0#constructors
- https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.symmetricalgorithm.key?view=net-6.0#system-security-cryptography-symmetricalgorithm-key
subcategory:
- vuln
technology:
- .net
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration
shortlink: https://sg.run/xjrA
semgrep.dev:
rule:
r_id: 36774
rv_id: 1262624
rule_id: KxU3Nq
version_id: rxTAK2O
url: https://semgrep.dev/playground/r/rxTAK2O/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration
origin: community
languages:
- csharp
mode: taint
pattern-sources:
- patterns:
- pattern-inside: (System.Random $RNG).NextBytes($KEY); ...
- pattern: $KEY
pattern-sinks:
- pattern-either:
- patterns:
- pattern: ($KEYTYPE $CIPHER).Key = $SINK;
- focus-metavariable: $SINK
- metavariable-pattern:
metavariable: $KEYTYPE
pattern-either:
- pattern: SymmetricAlgorithm
- pattern: Aes
- pattern: Rijndael
- pattern: DES
- pattern: TripleDES
- pattern: RC2
- pattern: new AesGcm(...)
- pattern: new AesCcm(...)
- pattern: new ChaCha20Poly1305(...)
- id: html.security.plaintext-http-link.plaintext-http-link
metadata:
category: security
technology:
- html
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
confidence: HIGH
subcategory:
- vuln
references:
- https://cwe.mitre.org/data/definitions/319.html
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/html.security.plaintext-http-link.plaintext-http-link
shortlink: https://sg.run/RA5q
semgrep.dev:
rule:
r_id: 39193
rv_id: 1262976
rule_id: AbUnNo
version_id: xyTjzRL
url: https://semgrep.dev/playground/r/xyTjzRL/html.security.plaintext-http-link.plaintext-http-link
origin: community
patterns:
- pattern: <a href="$URL">...</a>
- metavariable-regex:
metavariable: $URL
regex: ^(?i)http://
message: This link points to a plaintext HTTP URL. Prefer an encrypted HTTPS URL
if possible.
severity: WARNING
languages:
- html
- id: java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils
message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision
resistant and is therefore not suitable as a cryptographic signature. Use HMAC
instead.
languages:
- java
severity: WARNING
metadata:
functional-categories:
- crypto::search::hash-algorithm::org.apache.commons
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-328: Use of Weak Hash'
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils
shortlink: https://sg.run/AWL2
semgrep.dev:
rule:
r_id: 39194
rv_id: 1263012
rule_id: BYUGK0
version_id: WrTqK7K
url: https://semgrep.dev/playground/r/WrTqK7K/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils
origin: community
patterns:
- pattern: |
$DU.$GET_ALGO().digest(...)
- metavariable-pattern:
metavariable: $GET_ALGO
pattern: getMd5Digest
- metavariable-pattern:
metavariable: $DU
pattern: DigestUtils
- focus-metavariable: $GET_ALGO
fix: |
getSha512Digest
- id: yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection
message: Using input or workflow parameters in here-scripts can lead to command
injection or code injection. Convert the parameters to env variables instead.
languages:
- yaml
metadata:
category: security
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
owasp:
- "A03:2021 \u2013 Injection"
confidence: MEDIUM
likelihood: MEDIUM
impact: HIGH
subcategory:
- vuln
references:
- https://github.com/argoproj/argo-workflows/issues/5061
- https://github.com/argoproj/argo-workflows/issues/5114#issue-808865370
technology:
- ci
- argo
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
- Command Injection
source: https://semgrep.dev/r/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection
shortlink: https://sg.run/yqeZ
semgrep.dev:
rule:
r_id: 40768
rv_id: 1151472
rule_id: 10U0zW
version_id: xyTp17z
url: https://semgrep.dev/playground/r/xyTp17z/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection
origin: community
severity: ERROR
patterns:
- pattern-inside: |
apiVersion: $VERSION
...
- metavariable-regex:
metavariable: $VERSION
regex: (argoproj.io.*)
- pattern-either:
- patterns:
- pattern-inside: |
command:
...
- $LANG
...
...
source:
$SCRIPT
- metavariable-regex:
metavariable: $LANG
regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).*
- metavariable-pattern:
metavariable: $SCRIPT
pattern-either:
- pattern-regex: (.*{{.*inputs.parameters.*}}.*)
- pattern-regex: (.*{{.*workflow.parameters.*}}.*)
- focus-metavariable: $SCRIPT
- patterns:
- pattern-either:
- pattern-inside: |
container:
...
command: $LANG
...
args: $PARAM
- pattern-inside: |
containerSet:
...
containers:
- ...
command: $LANG
...
args: $PARAM
- metavariable-regex:
metavariable: $LANG
regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).*
- metavariable-pattern:
metavariable: $PARAM
pattern-either:
- pattern-regex: (.*{{.*inputs.parameters.*}}.*)
- pattern-regex: (.*{{.*workflow.parameters.*}}.*)
- focus-metavariable: $PARAM
- id: python.cryptography.security.empty-aes-key.empty-aes-key
message: Potential empty AES encryption key. Using an empty key in AES encryption
can result in weak encryption and may allow attackers to easily decrypt sensitive
data. Ensure that a strong, non-empty key is used for AES encryption.
patterns:
- pattern: AES.new("",...)
languages:
- python
severity: WARNING
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
- 'CWE-310: Cryptographic Issues'
references:
- https://cwe.mitre.org/data/definitions/327.html
- https://cwe.mitre.org/data/definitions/310.html
category: security
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
owasp: A6:2017 misconfiguration
functional-categories:
- crypto::search::key-length::pycrypto
- crypto::search::key-length::pycryptodome
technology:
- python
- pycrypto
- pycryptodome
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.cryptography.security.empty-aes-key.empty-aes-key
shortlink: https://sg.run/zQ9G
semgrep.dev:
rule:
r_id: 44817
rv_id: 946105
rule_id: OrUADK
version_id: 8KTKjRg
url: https://semgrep.dev/playground/r/8KTKjRg/python.cryptography.security.empty-aes-key.empty-aes-key
origin: community
- id: dockerfile.security.missing-user-entrypoint.missing-user-entrypoint
patterns:
- pattern: |
ENTRYPOINT $...VARS
- pattern-not-inside: |
USER $USER
...
fix: |
USER non-root
ENTRYPOINT $...VARS
message: By not specifying a USER, a program in the container may run as 'root'.
This is a security hazard. If an attacker can control a process running as root,
they may have control over the container. Ensure that the last USER in a Dockerfile
is a USER other than 'root'.
severity: ERROR
languages:
- dockerfile
metadata:
cwe:
- 'CWE-269: Improper Privilege Management'
category: security
technology:
- dockerfile
confidence: MEDIUM
owasp:
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint
shortlink: https://sg.run/k281
semgrep.dev:
rule:
r_id: 47272
rv_id: 1262659
rule_id: ReUW9E
version_id: o5TbD21
url: https://semgrep.dev/playground/r/o5TbD21/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint
origin: community
- id: terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions
pattern-either:
- pattern: |
resource "aws_config_configuration_aggregator" $ANYTHING {
...
account_aggregation_source {
...
regions = ...
...
}
...
}
- pattern: |
resource "aws_config_configuration_aggregator" $ANYTHING {
...
organization_aggregation_source {
...
regions = ...
...
}
...
}
message: The AWS configuration aggregator does not aggregate all AWS Config region.
This may result in unmonitored configuration in regions that are thought to be
unused. Configure the aggregator with all_regions for the source.
languages:
- hcl
severity: WARNING
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A09:2021 - Security Logging and Monitoring Failures
- A09:2025 - Security Logging & Alerting Failures
cwe:
- 'CWE-778: Insufficient Logging'
references:
- https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insufficient Logging
source: https://semgrep.dev/r/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions
shortlink: https://sg.run/O6A7
semgrep.dev:
rule:
r_id: 47275
rv_id: 1263703
rule_id: DbUo7v
version_id: A8Tgdwv
url: https://semgrep.dev/playground/r/A8Tgdwv/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions
origin: community
- id: yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext
patterns:
- pattern-inside: |
containers:
...
- pattern-inside: |
- $NAME: $CONTAINER
...
- pattern: |
image: ...
...
- pattern-not: |
image: ...
...
securityContext:
...
- metavariable-regex:
metavariable: $NAME
regex: name
- focus-metavariable: $NAME
fix: |
securityContext:
allowPrivilegeEscalation: false
$NAME
message: In Kubernetes, each pod runs in its own isolated environment with its own
set of security policies. However, certain container images may contain `setuid`
or `setgid` binaries that could allow an attacker to perform privilege escalation
and gain access to sensitive resources. To mitigate this risk, it's recommended
to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation`
set to `false`. This will prevent the container from running any privileged processes
and limit the impact of any potential attacks. By adding a `securityContext` to
your Kubernetes pod, you can help to ensure that your containerized applications
are more secure and less vulnerable to privilege escalation attacks.
metadata:
cwe:
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
owasp:
- A05:2021 - Security Misconfiguration
- A06:2017 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation
- https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
- https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt
- https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag
category: security
technology:
- kubernetes
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext
shortlink: https://sg.run/eleR
semgrep.dev:
rule:
r_id: 47276
rv_id: 1263931
rule_id: WAU5J6
version_id: 2KTv2j8
url: https://semgrep.dev/playground/r/2KTv2j8/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext
origin: community
languages:
- yaml
severity: WARNING
- id: yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true
patterns:
- pattern-inside: |
containers:
...
- pattern-inside: |
- name: $CONTAINER
...
- pattern-inside: |
image: ...
...
- pattern-inside: |
securityContext:
...
- pattern: |
allowPrivilegeEscalation: $TRUE
- metavariable-pattern:
metavariable: $TRUE
pattern: |
true
- focus-metavariable: $TRUE
fix: |
false
message: In Kubernetes, each pod runs in its own isolated environment with its own set
of security policies. However, certain container images may contain `setuid`
or `setgid` binaries that could allow an attacker to perform privilege escalation
and gain access to sensitive resources. To mitigate this risk, it's recommended
to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation`
set to `false`. This will prevent the container from running any privileged processes
and limit the impact of any potential attacks. In the container `$CONTAINER`
this parameter is set to `true` which makes this container much more vulnerable
to privelege escalation attacks.
metadata:
cwe:
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
owasp:
- A05:2021 - Security Misconfiguration
- A06:2017 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation
- https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
- https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt
- https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag
category: security
technology:
- kubernetes
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true
shortlink: https://sg.run/vw3W
semgrep.dev:
rule:
r_id: 47277
rv_id: 1263932
rule_id: 0oUkqQ
version_id: X0Tzyqr
url: https://semgrep.dev/playground/r/X0Tzyqr/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true
origin: community
languages:
- yaml
severity: WARNING
- id: terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled
patterns:
- pattern: |
resource "aws_docdb_cluster" $ANYTHING {
...
}
- pattern-not-inside: |
resource "aws_docdb_cluster" $ANYTHING {
...
enabled_cloudwatch_logs_exports = [..., "audit", ...]
...
}
message: Auditing is not enabled for DocumentDB. To ensure that you are able to
accurately audit the usage of your DocumentDB cluster, you should enable auditing
and export logs to CloudWatch.
languages:
- hcl
severity: INFO
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A09:2021 - Security Logging and Monitoring Failures
- A09:2025 - Security Logging & Alerting Failures
cwe:
- 'CWE-778: Insufficient Logging'
references:
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/docdb_cluster#enabled_cloudwatch_logs_exports
- https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/
subcategory:
- audit
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insufficient Logging
source: https://semgrep.dev/r/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled
shortlink: https://sg.run/xJYP
semgrep.dev:
rule:
r_id: 48630
rv_id: 1263705
rule_id: AbU1WN
version_id: DkTRbA4
url: https://semgrep.dev/playground/r/DkTRbA4/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled
origin: community
- id: terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags
patterns:
- pattern: |
resource "aws_ecr_repository" $ANYTHING {
...
}
- pattern-not-inside: |
resource "aws_ecr_repository" $ANYTHING {
...
image_tag_mutability = "IMMUTABLE"
...
}
message: The ECR repository allows tag mutability. Image tags could be overwritten
with compromised images. ECR images should be set to IMMUTABLE to prevent code
injection through image mutation. This can be done by setting `image_tag_mutability`
to IMMUTABLE.
languages:
- hcl
severity: WARNING
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software or Data Integrity Failures
cwe:
- 'CWE-345: Insufficient Verification of Data Authenticity'
references:
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository#image_tag_mutability
- https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures/
subcategory:
- audit
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags
shortlink: https://sg.run/ZEeL
semgrep.dev:
rule:
r_id: 48635
rv_id: 1263716
rule_id: KxUB4o
version_id: A8Tgdwd
url: https://semgrep.dev/playground/r/A8Tgdwd/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags
origin: community
- id: terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal
patterns:
- pattern-inside: |
resource "aws_ecr_repository_policy" $ANYTHING {
...
}
- pattern-either:
- patterns:
- pattern: policy = "$JSONPOLICY"
- metavariable-pattern:
metavariable: $JSONPOLICY
language: json
patterns:
- pattern-not-inside: |
{..., "Effect": "Deny", ...}
- pattern-either:
- pattern: |
{..., "Principal": "*", ...}
- pattern: |
{..., "Principal": [..., "*", ...], ...}
- pattern: |
{..., "Principal": { "AWS": "*" }, ...}
- pattern: |
{..., "Principal": { "AWS": [..., "*", ...] }, ...}
- patterns:
- pattern-inside: policy = jsonencode(...)
- pattern-not-inside: |
{..., Effect = "Deny", ...}
- pattern-either:
- pattern: |
{..., Principal = "*", ...}
- pattern: |
{..., Principal = [..., "*", ...], ...}
- pattern: |
{..., Principal = { AWS = "*" }, ...}
- pattern: |
{..., Principal = { AWS = [..., "*", ...] }, ...}
message: Detected wildcard access granted in your ECR repository policy principal.
This grants access to all users, including anonymous users (public access). Instead,
limit principals, actions and resources to what you need according to least privilege.
metadata:
category: security
technology:
- aws
- terraform
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe:
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
references:
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository_policy
- https://docs.aws.amazon.com/lambda/latest/operatorguide/wildcard-permissions-iam.html
- https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/monitor-amazon-ecr-repositories-for-wildcard-permissions-using-aws-cloudformation-and-aws-config.html
- https://cwe.mitre.org/data/definitions/732.html
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal
shortlink: https://sg.run/nzqb
semgrep.dev:
rule:
r_id: 48636
rv_id: 1263717
rule_id: qNUzov
version_id: BjTkZ6A
url: https://semgrep.dev/playground/r/BjTkZ6A/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal
origin: community
languages:
- hcl
severity: WARNING
- id: java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb
pattern: $CIPHER.getInstance("=~/AES/ECB.*/")
metadata:
functional-categories:
- crypto::search::mode::javax.crypto
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb
shortlink: https://sg.run/dB2Y
semgrep.dev:
rule:
r_id: 48734
rv_id: 1263009
rule_id: WAU2yA
version_id: A8TgdEo
url: https://semgrep.dev/playground/r/A8TgdEo/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb
origin: community
message: 'Use of AES with ECB mode detected. ECB doesn''t provide message confidentiality
and is not semantically secure so should not be used. Instead, use a strong,
secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions
for more information.'
severity: WARNING
languages:
- java
- id: java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish
pattern: $CIPHER.getInstance("Blowfish")
metadata:
functional-categories:
- crypto::search::symmetric-algorithm::javax.crypto
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish
shortlink: https://sg.run/ZE4n
semgrep.dev:
rule:
r_id: 48735
rv_id: 1263010
rule_id: 0oUR28
version_id: BjTkZy0
url: https://semgrep.dev/playground/r/BjTkZy0/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish
origin: community
message: 'Use of Blowfish was detected. Blowfish uses a 64-bit block size that makes
it vulnerable to birthday attacks, and is therefore considered non-compliant. Instead,
use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions
for more information.'
severity: WARNING
languages:
- java
- id: java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes
pattern-either:
- patterns:
- pattern-either:
- pattern-inside: |
import javax;
...
- pattern-either:
- pattern: javax.crypto.Cipher.getInstance("AES")
- pattern: (javax.crypto.Cipher $CIPHER).getInstance("AES")
- patterns:
- pattern-either:
- pattern-inside: |
import javax.*;
...
- pattern-inside: |
import javax.crypto;
...
- pattern-either:
- pattern: crypto.Cipher.getInstance("AES")
- pattern: (crypto.Cipher $CIPHER).getInstance("AES")
- patterns:
- pattern-either:
- pattern-inside: |
import javax.crypto.*;
...
- pattern-inside: |
import javax.crypto.Cipher;
...
- pattern-either:
- pattern: Cipher.getInstance("AES")
- pattern: (Cipher $CIPHER).getInstance("AES")
metadata:
functional-categories:
- crypto::search::mode::javax.crypto
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes
shortlink: https://sg.run/nzKO
semgrep.dev:
rule:
r_id: 48736
rv_id: 1263011
rule_id: KxUB7Z
version_id: DkTRbwy
url: https://semgrep.dev/playground/r/DkTRbwy/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes
origin: community
message: 'Use of AES with no settings detected. By default, java.crypto.Cipher uses
ECB mode. ECB doesn''t provide message confidentiality and is not semantically
secure so should not be used. Instead, use a strong, secure cipher: java.crypto.Cipher.getInstance("AES/CBC/PKCS7PADDING").
See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for
more information.'
severity: WARNING
languages:
- java
- id: java.lang.security.audit.crypto.use-of-rc2.use-of-rc2
pattern: $CIPHER.getInstance("RC2")
metadata:
functional-categories:
- crypto::search::symmetric-algorithm::javax.crypto
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2
shortlink: https://sg.run/EEvA
semgrep.dev:
rule:
r_id: 48737
rv_id: 1263014
rule_id: qNUzXG
version_id: K3TKkg0
url: https://semgrep.dev/playground/r/K3TKkg0/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2
origin: community
message: 'Use of RC2 was detected. RC2 is vulnerable to related-key attacks, and
is therefore considered non-compliant. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING").
See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for
more information.'
severity: WARNING
languages:
- java
- id: java.lang.security.audit.crypto.use-of-rc4.use-of-rc4
pattern: $CIPHER.getInstance("RC4")
metadata:
functional-categories:
- crypto::search::symmetric-algorithm::javax.crypto
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
category: security
technology:
- java
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
- https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4
shortlink: https://sg.run/7OYR
semgrep.dev:
rule:
r_id: 48738
rv_id: 1263015
rule_id: lBUw8k
version_id: qkTR7vk
url: https://semgrep.dev/playground/r/qkTR7vk/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4
origin: community
message: 'Use of RC4 was detected. RC4 is vulnerable to several attacks, including
stream cipher attacks and bit flipping attacks. Instead, use a strong, secure
cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions
for more information.'
severity: WARNING
languages:
- java
- id: problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request
message: Detected an HTTP request sent via HttpGet. This could lead to sensitive
information being sent over an insecure channel. Instead, it is recommended to
send requests over HTTPS.
severity: WARNING
metadata:
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
category: security
cwe: 'CWE-319: Cleartext Transmission of Sensitive Information'
owasp: A03:2017 - Sensitive Data Exposure
references:
- https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URLConnection.html
- https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URL.html#openConnection()
subcategory:
- vuln
technology:
- java
vulnerability: Insecure Transport
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request
shortlink: https://sg.run/QE2q
semgrep.dev:
rule:
r_id: 48942
rv_id: 946061
rule_id: 6JUOJ2
version_id: WrTEo9G
url: https://semgrep.dev/playground/r/WrTEo9G/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request
origin: community
languages:
- java
fix-regex:
regex: '[Hh][Tt][Tt][Pp]://'
replacement: https://
count: 1
patterns:
- pattern: |
"=~/[Hh][Tt][Tt][Pp]://.*/"
- pattern-inside: |
$R = new HttpGet("=~/[Hh][Tt][Tt][Pp]://.*/");
...
$CLIENT. ... .execute($R, ...);
- id: terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted
patterns:
- pattern: |
resource "aws_ebs_volume" $ANYTHING {
...
}
- pattern-not: |
resource "aws_ebs_volume" $ANYTHING {
...
encrypted = true
...
}
message: The AWS EBS volume is unencrypted. The volume, the disk I/O and any derived
snapshots could be read if compromised. Volumes should be encrypted to ensure
sensitive data is stored securely.
languages:
- hcl
severity: WARNING
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A03:2017 - Sensitive Data Exposure
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
cwe:
- 'CWE-311: Missing Encryption of Sensitive Data'
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ebs_volume#encrypted
- https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html
subcategory:
- audit
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted
shortlink: https://sg.run/6ZbY
semgrep.dev:
rule:
r_id: 50759
rv_id: 1263708
rule_id: YGUKl1
version_id: K3TKk1Z
url: https://semgrep.dev/playground/r/K3TKk1Z/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted
origin: community
- id: terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled
patterns:
- pattern: |
resource "aws_launch_template" $ANYTHING {
...
}
- pattern-not-inside: |
resource "aws_launch_template" $ANYTHING {
...
metadata_options {
...
http_endpoint = "disabled"
...
}
...
}
- pattern-not-inside: |
resource "aws_launch_template" $ANYTHING {
...
metadata_options {
...
http_tokens = "required"
...
}
...
}
message: The EC2 launch template has Instance Metadata Service Version 1 (IMDSv1)
enabled. IMDSv2 introduced session authentication tokens which improve security
when talking to IMDS. You should either disable IMDS or require the use of IMDSv2.
languages:
- hcl
severity: WARNING
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe:
- 'CWE-1390: Weak Authentication'
references:
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_configuration#metadata_options
- https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service
subcategory:
- audit
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled
shortlink: https://sg.run/pg9J
semgrep.dev:
rule:
r_id: 50762
rv_id: 1263712
rule_id: zdU0Wo
version_id: JdTzx88
url: https://semgrep.dev/playground/r/JdTzx88/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled
origin: community
- id: terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address
patterns:
- pattern-either:
- pattern: |
resource "aws_subnet" $ANYTHING {
...
map_public_ip_on_launch = true
...
}
- pattern: |
resource "aws_default_subnet" $ANYTHING {
...
}
- pattern-not: |
resource "aws_default_subnet" $ANYTHING {
...
map_public_ip_on_launch = false
...
}
message: Resources in the AWS subnet are assigned a public IP address. Resources
should not be exposed on the public internet, but should have access limited to
consumers required for the function of your application. Set `map_public_ip_on_launch`
to false so that resources are not publicly-accessible.
languages:
- hcl
severity: WARNING
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-1220: Insufficient Granularity of Access Control'
references:
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/subnet#map_public_ip_on_launch
- https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-instance-addressing.html#concepts-public-addresses
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address
shortlink: https://sg.run/XJZw
semgrep.dev:
rule:
r_id: 50764
rv_id: 1263744
rule_id: 2ZUo79
version_id: d6Tyxdb
url: https://semgrep.dev/playground/r/d6Tyxdb/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address
origin: community
- id: clojure.lang.security.use-of-md5.use-of-md5
languages:
- clojure
severity: WARNING
message: MD5 hash algorithm detected. This is not collision resistant and leads
to easily-cracked password hashes. Replace with current recommended hashing algorithms.
metadata:
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
technology:
- clojure
source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/weak-hash-function-md5.yml
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-328: Use of Weak Hash'
author: Gabriel Marquet <gab.marquet@gmail.com>
category: security
subcategory:
- vuln
confidence: HIGH
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/clojure.lang.security.use-of-md5.use-of-md5
shortlink: https://sg.run/BgPx
semgrep.dev:
rule:
r_id: 52195
rv_id: 1262609
rule_id: nJU1ep
version_id: 0bTKz2B
url: https://semgrep.dev/playground/r/0bTKz2B/clojure.lang.security.use-of-md5.use-of-md5
origin: community
pattern-either:
- pattern: (MessageDigest/getInstance "MD5")
- pattern: (MessageDigest/getInstance MessageDigestAlgorithms/MD5)
- pattern: (MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5)
- pattern: (java.security.MessageDigest/getInstance "MD5")
- pattern: (java.security.MessageDigest/getInstance MessageDigestAlgorithms/MD5)
- pattern: (java.security.MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5)
- id: generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak
patterns:
- pattern-regex: ^(AIza[0-9A-Za-z_-]{35}(?!\S))$
message: Detects potential Google Maps API keys in code
languages:
- generic
severity: WARNING
metadata:
description: Detects potential Google Maps API keys in code
severity: MEDIUM
category: security
confidence: MEDIUM
impact: HIGH
likelihood: MEDIUM
subcategory:
- audit
owasp:
- A3:2017 Sensitive Data Exposure
references:
- https://ozguralp.medium.com/unauthorized-google-maps-api-key-usage-cases-and-why-you-need-to-care-1ccb28bf21e
cwe:
- 'CWE-538: Insertion of Sensitive Information into Externally-Accessible File
or Directory'
technology:
- Google Maps
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak
shortlink: https://sg.run/DL5d
semgrep.dev:
rule:
r_id: 52196
rv_id: 945530
rule_id: EwU3kN
version_id: NdTqkGz
url: https://semgrep.dev/playground/r/NdTqkGz/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak
origin: community
- id: terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted
patterns:
- pattern: |
resource "aws_kinesis_stream" $ANYTHING {
...
}
- pattern-not: |
resource "aws_kinesis_stream" $ANYTHING {
...
encryption_type = "KMS"
...
}
message: The AWS Kinesis stream does not encrypt data at rest. The data could be
read if the Kinesis stream storage layer is compromised. Enable Kinesis stream
server-side encryption.
languages:
- hcl
severity: WARNING
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A03:2017 - Sensitive Data Exposure
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
cwe:
- 'CWE-311: Missing Encryption of Sensitive Data'
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/kinesis_stream#encryption_type
- https://docs.aws.amazon.com/streams/latest/dev/server-side-encryption.html
subcategory:
- audit
likelihood: LOW
impact: HIGH
confidence: MEDIUM
rule-origin-note: published from /src/aws-kinesis-stream-unencrypted.yml in None
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted
shortlink: https://sg.run/KZ0L
semgrep.dev:
rule:
r_id: 52199
rv_id: 1263728
rule_id: 8GU72N
version_id: pZT037O
url: https://semgrep.dev/playground/r/pZT037O/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted
origin: community
- id: terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal
patterns:
- pattern-either:
- pattern-inside: |
resource "aws_sqs_queue_policy" $ANYTHING {
...
}
- pattern-inside: |
resource "aws_sqs_queue" $ANYTHING {
...
}
- pattern-either:
- patterns:
- pattern: policy = "$JSONPOLICY"
- metavariable-pattern:
metavariable: $JSONPOLICY
language: json
patterns:
- pattern-not-inside: |
{..., "Effect": "Deny", ...}
- pattern-either:
- pattern: |
{..., "Principal": "*", ...}
- pattern: |
{..., "Principal": [..., "*", ...], ...}
- pattern: |
{..., "Principal": { "AWS": "*" }, ...}
- pattern: |
{..., "Principal": { "AWS": [..., "*", ...] }, ...}
- pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnNotLike\": {\n \"aws:SourceArn\":
...\n }\n},\n...}\n"
- pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnLike\": {\n \"aws:SourceArn\":
...\n }\n},\n...}\n"
- pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnEquals\": {\n \"aws:SourceArn\":
...\n }\n},\n...}\n"
- pattern-not-inside: "{..., \n\"Condition\": {\n \"StringNotLike\": {\n
\ \"aws:PrincipalARN\": ...\n }\n},\n...}\n"
- patterns:
- pattern-inside: policy = jsonencode(...)
- pattern-not-inside: |
{..., Effect = "Deny", ...}
- pattern-not-inside: "{..., \nCondition = {\n ArnNotLike = {\n \"aws:SourceArn\"
= ...\n }\n},\n...}\n"
- pattern-not-inside: "{..., \nCondition = {\n ArnLike = {\n \"aws:SourceArn\"
= ...\n }\n},\n...}\n"
- pattern-not-inside: "{..., \nCondition = {\n ArnEquals = {\n \"aws:SourceArn\"
= ...\n }\n}\n...}\n"
- pattern-not-inside: "{..., \nCondition = {\n StringNotLike = {\n \"aws:PrincipalARN\"
= ...\n }\n},\n...}\n"
- pattern-either:
- pattern: |
{..., Principal = "*", ...}
- pattern: |
{..., Principal = [..., "*", ...], ...}
- pattern: |
{..., Principal = { AWS = "*" }, ...}
- pattern: |
{..., Principal = { AWS = [..., "*", ...] }, ...}
message: Wildcard used in your SQS queue policy principal. This grants access to
all users, including anonymous users (public access). Unless you explicitly require
anyone on the internet to be able to read or write to your queue, limit principals,
actions and resources to what you need according to least privilege.
metadata:
category: security
technology:
- aws
- terraform
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe:
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
references:
- https://cwe.mitre.org/data/definitions/732.html
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue_policy
- https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-security-best-practices.html
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
rule-origin-note: published from /src/aws-sqs-queue-policy-wildcard-principal.yml
in None
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal
shortlink: https://sg.run/z3eW
semgrep.dev:
rule:
r_id: 53517
rv_id: 1263741
rule_id: PeUl9d
version_id: O9TpxgE
url: https://semgrep.dev/playground/r/O9TpxgE/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal
origin: community
languages:
- hcl
severity: ERROR
- id: terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn
patterns:
- pattern: |
resource "aws_lambda_permission" $ANYTHING {
...
principal = "$PRINCIPAL"
...
}
- pattern-not: |
resource "aws_lambda_permission" $ANYTHING {
...
source_arn = ...
...
}
- metavariable-regex:
metavariable: $PRINCIPAL
regex: .*[.]amazonaws[.]com$
message: The AWS Lambda permission has an AWS service principal but does not specify
a source ARN. If you grant permission to a service principal without specifying
the source, other accounts could potentially configure resources in their account
to invoke your Lambda function. Set the source_arn value to the ARN of the AWS
resource that invokes the function, eg. an S3 bucket, CloudWatch Events Rule,
API Gateway, or SNS topic.
languages:
- hcl
severity: ERROR
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe:
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
references:
- https://cwe.mitre.org/data/definitions/732.html
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_permission
- https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-lambda-permission.html
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn
shortlink: https://sg.run/kOP7
semgrep.dev:
rule:
r_id: 54772
rv_id: 1263732
rule_id: OrU9Ox
version_id: 1QTypq5
url: https://semgrep.dev/playground/r/1QTypq5/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn
origin: community
- id: terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active
patterns:
- pattern: |
resource "aws_lambda_function" $ANYTHING {
...
}
- pattern-not: |
resource "aws_lambda_function" $ANYTHING {
...
tracing_config {
...
mode = "Active"
...
}
...
}
message: The AWS Lambda function does not have active X-Ray tracing enabled. X-Ray
tracing enables end-to-end debugging and analysis of all function activity. This
makes it easier to trace the flow of logs and identify bottlenecks, slow downs
and timeouts.
languages:
- hcl
severity: INFO
metadata:
category: security
technology:
- aws
- terraform
owasp:
- A09:2021 Security Logging and Monitoring Failures
cwe:
- 'CWE-778: Insufficient Logging'
references:
- https://cwe.mitre.org/data/definitions/778.html
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_function#mode
- https://docs.aws.amazon.com/lambda/latest/dg/services-xray.html
subcategory:
- audit
likelihood: LOW
impact: LOW
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insufficient Logging
source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active
shortlink: https://sg.run/wO2Y
semgrep.dev:
rule:
r_id: 54773
rv_id: 946713
rule_id: eqUl1O
version_id: QkTZ6vk
url: https://semgrep.dev/playground/r/QkTZ6vk/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active
origin: community
- id: java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization
patterns:
- pattern-either:
- patterns:
- pattern-inside: |
ObjectMapper $OM = new ObjectMapper(...);
...
- pattern-inside: |
$OM.enableDefaultTyping();
...
- pattern: $OM.readValue($JSON, ...);
- patterns:
- pattern-inside: |
class $CLASS {
...
@JsonTypeInfo(use = Id.CLASS,...)
$TYPE $VAR;
...
}
- metavariable-regex:
metavariable: $TYPE
regex: (Object|Serializable|Comparable)
- pattern: $OM.readValue($JSON, $CLASS.class);
- patterns:
- pattern-inside: |
class $CLASS {
...
ObjectMapper $OM;
...
$INITMETHODTYPE $INITMETHOD(...) {
...
$OM = new ObjectMapper();
...
$OM.enableDefaultTyping();
...
}
...
}
- pattern-inside: "$METHODTYPE $METHOD(...) {\n ... \n}\n"
- pattern: $OM.readValue($JSON, ...);
message: When using Jackson to marshall/unmarshall JSON to Java objects, enabling
default typing is dangerous and can lead to RCE. If an attacker can control `$JSON`
it might be possible to provide a malicious JSON which can be used to exploit
unsecure deserialization. In order to prevent this issue, avoid to enable default
typing (globally or by using "Per-class" annotations) and avoid using `Object`
and other dangerous types for member variable declaration which creating classes
for Jackson based deserialization.
languages:
- java
severity: WARNING
metadata:
category: security
subcategory:
- audit
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
confidence: MEDIUM
likelihood: LOW
impact: HIGH
owasp:
- A8:2017 Insecure Deserialization
- A8:2021 Software and Data Integrity Failures
references:
- https://swapneildash.medium.com/understanding-insecure-implementation-of-jackson-deserialization-7b3d409d2038
- https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
- https://adamcaudill.com/2017/10/04/exploiting-jackson-rce-cve-2017-7525/
technology:
- jackson
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization
shortlink: https://sg.run/GDop
semgrep.dev:
rule:
r_id: 56948
rv_id: 945724
rule_id: QrUD20
version_id: 2KTYbA9
url: https://semgrep.dev/playground/r/2KTYbA9/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization
origin: community
- id: java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing
severity: ERROR
metadata:
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.2 Insecue XML Deserialization
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
version: '4'
references:
- https://semgrep.dev/blog/2022/xml-security-in-java
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
- https://blog.sonarsource.com/secure-xml-processor
- https://xerces.apache.org/xerces2-j/features.html
category: security
technology:
- java
- xml
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing
shortlink: https://sg.run/Gj32
semgrep.dev:
rule:
r_id: 59048
rv_id: 1263061
rule_id: j2Udpk
version_id: YDTZeko
url: https://semgrep.dev/playground/r/YDTZeko/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing
origin: community
message: DOCTYPE declarations are enabled for this SAXParserFactory. This is vulnerable
to XML external entity attacks. Disable this by setting the feature `http://apache.org/xml/features/disallow-doctype-decl`
to true. Alternatively, allow DOCTYPE declarations and only prohibit external
entities declarations. This can be done by setting the features `http://xml.org/sax/features/external-general-entities`
and `http://xml.org/sax/features/external-parameter-entities` to false. NOTE -
The previous links are not meant to be clicked. They are the literal config key
values that are supposed to be used to disable these features. For more information,
see https://semgrep.dev/docs/cheat-sheets/java-xxe/#3a-documentbuilderfactory.
mode: taint
pattern-sources:
- by-side-effect: true
patterns:
- pattern-either:
- pattern: |
$FACTORY = SAXParserFactory.newInstance();
- patterns:
- pattern: $FACTORY
- pattern-inside: |
class $C {
...
$V $FACTORY = SAXParserFactory.newInstance();
...
}
- pattern-not-inside: |
class $C {
...
$V $FACTORY = SAXParserFactory.newInstance();
static {
...
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
...
}
...
}
- pattern-not-inside: |
class $C {
...
$V $FACTORY = SAXParserFactory.newInstance();
static {
...
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
...
}
...
}
- pattern-not-inside: |
class $C {
...
$V $FACTORY = SAXParserFactory.newInstance();
static {
...
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
}
...
}
pattern-sinks:
- patterns:
- pattern: $FACTORY.newSAXParser();
pattern-sanitizers:
- by-side-effect: true
pattern-either:
- patterns:
- pattern-either:
- pattern: |
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
- pattern: |
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
- pattern: |
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
- focus-metavariable: $FACTORY
- patterns:
- pattern-either:
- pattern-inside: |
class $C {
...
$T $M(...) {
...
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl",
true);
...
}
...
}
- pattern-inside: |
class $C {
...
$T $M(...) {
...
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
}
...
}
- pattern-inside: |
class $C {
...
$T $M(...) {
...
$FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
...
$FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false);
...
}
...
}
- pattern: $M($X)
- focus-metavariable: $X
fix: |
$FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
$FACTORY.newSAXParser();
languages:
- java
- id: java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled
severity: ERROR
metadata:
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.2 Insecue XML Deserialization
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
version: '4'
references:
- https://semgrep.dev/blog/2022/xml-security-in-java
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
- https://blog.sonarsource.com/secure-xml-processor
- https://xerces.apache.org/xerces2-j/features.html
category: security
technology:
- java
- xml
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled
shortlink: https://sg.run/1wyQ
semgrep.dev:
rule:
r_id: 59622
rv_id: 1263062
rule_id: v8UeQ1
version_id: 6xT29GK
url: https://semgrep.dev/playground/r/6xT29GK/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled
origin: community
message: DOCTYPE declarations are enabled for this TransformerFactory. This is vulnerable
to XML external entity attacks. Disable this by setting the attributes "accessExternalDTD"
and "accessExternalStylesheet" to "".
mode: taint
pattern-sources:
- by-side-effect: true
patterns:
- pattern-either:
- pattern: |
$FACTORY = TransformerFactory.newInstance();
- patterns:
- pattern: $FACTORY
- pattern-inside: |
class $C {
...
$V $FACTORY = TransformerFactory.newInstance();
...
}
- pattern-not-inside: |
class $C {
...
$V $FACTORY = TransformerFactory.newInstance();
static {
...
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
...
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
...
}
...
}
- pattern-not-inside: |
class $C {
...
$V $FACTORY = TransformerFactory.newInstance();
static {
...
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
...
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
...
}
...
}
- pattern-not-inside: |
class $C {
...
$V $FACTORY = TransformerFactory.newInstance();
static {
...
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
...
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
...
}
...
}
- pattern-not-inside: |
class $C {
...
$V $FACTORY = TransformerFactory.newInstance();
static {
...
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
...
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
...
}
...
}
pattern-sinks:
- patterns:
- pattern: $FACTORY.newTransformer(...);
pattern-sanitizers:
- by-side-effect: true
pattern-either:
- patterns:
- pattern-either:
- pattern: |
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ...
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
- pattern: |
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
...
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
- pattern: |
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ...
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
- pattern: |
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
...
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
- focus-metavariable: $FACTORY
- patterns:
- pattern-either:
- pattern-inside: |
class $C {
...
$T $M(...) {
...
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
...
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
...
}
...
}
- pattern-inside: |
class $C {
...
$T $M(...) {
...
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
...
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
...
}
...
}
- pattern-inside: |
class $C {
...
$T $M(...) {
...
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
...
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
...
}
...
}
- pattern-inside: |
class $C {
...
$T $M(...) {
...
$FACTORY.setAttribute("=~/.*accessExternalDTD.*/", "");
...
$FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", "");
...
}
...
}
- pattern: $M($X)
- focus-metavariable: $X
fix: |
$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
$FACTORY.newTransformer(...);
languages:
- java
- id: java.android.security.exported_activity.exported_activity
patterns:
- pattern-not-inside: <activity ... android:exported="false" ... />
- pattern-inside: "<activity ... /> \n"
- pattern-either:
- pattern: |
<activity ... android:exported="true" ... />
- pattern: |
<activity ... <intent-filter> ... />
message: The application exports an activity. Any application on the device can
launch the exported activity which may compromise the integrity of your application
or its data. Ensure that any exported activities do not have privileged access
to your application's control plane.
languages:
- generic
severity: WARNING
paths:
exclude:
- sources/
- classes3.dex
- '*.so'
include:
- '*AndroidManifest.xml'
metadata:
category: security
subcategory:
- vuln
cwe:
- 'CWE-926: Improper Export of Android Application Components'
confidence: MEDIUM
likelihood: MEDIUM
impact: MEDIUM
owasp:
- A5:2021 Security Misconfiguration
technology:
- Android
references:
- https://cwe.mitre.org/data/definitions/926.html
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/java.android.security.exported_activity.exported_activity
shortlink: https://sg.run/eNGZ
semgrep.dev:
rule:
r_id: 60632
rv_id: 945629
rule_id: v8Ul0r
version_id: rxT6rGR
url: https://semgrep.dev/playground/r/rxT6rGR/java.android.security.exported_activity.exported_activity
origin: community
- id: dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile
patterns:
- pattern: |
RUN sudo ...
message: Avoid using sudo in Dockerfiles. Running processes as a non-root user can
help reduce the potential impact of configuration errors and security vulnerabilities.
metadata:
category: security
technology:
- dockerfile
cwe:
- 'CWE-250: Execution with Unnecessary Privileges'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://cwe.mitre.org/data/definitions/250.html
- https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#user
subcategory:
- audit
likelihood: LOW
impact: LOW
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile
shortlink: https://sg.run/80Q7
semgrep.dev:
rule:
r_id: 66384
rv_id: 1262661
rule_id: kxUlx1
version_id: pZT03zY
url: https://semgrep.dev/playground/r/pZT03zY/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile
origin: community
languages:
- dockerfile
severity: WARNING
- id: swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults
message: Potentially sensitive data was observed to be stored in UserDefaults, which
is not adequate protection of sensitive information. For data of a sensitive nature,
applications should leverage the Keychain.
severity: WARNING
metadata:
likelihood: LOW
impact: HIGH
confidence: MEDIUM
category: security
cwe:
- 'CWE-311: Missing Encryption of Sensitive Data'
masvs:
- 'MASVS-STORAGE-1: The app securely stores sensitive data'
owasp:
- A03:2017 - Sensitive Data Exposure
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
references:
- https://developer.apple.com/library/archive/documentation/Security/Conceptual/SecureCodingGuide/Articles/ValidatingInput.html
- https://mas.owasp.org/MASVS/controls/MASVS-STORAGE-1/
subcategory:
- vuln
technology:
- ios
- macos
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults
shortlink: https://sg.run/qvoO
semgrep.dev:
rule:
r_id: 66512
rv_id: 1263696
rule_id: KxUqoZ
version_id: 3ZT4Xy2
url: https://semgrep.dev/playground/r/3ZT4Xy2/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults
origin: community
languages:
- swift
options:
symbolic_propagation: true
patterns:
- pattern-either:
- patterns:
- pattern-either:
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: $KEY)
- pattern: |
UserDefaults.standard.set($VALUE, forKey: "$KEY")
- pattern: |
UserDefaults.standard.set($VALUE, forKey: $KEY)
- metavariable-regex:
metavariable: $VALUE
regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$
- focus-metavariable: $VALUE
- patterns:
- pattern-either:
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: $KEY)
- pattern: |
UserDefaults.standard.set($VALUE, forKey: "$KEY")
- pattern: |
UserDefaults.standard.set($VALUE, forKey: $KEY)
- metavariable-regex:
metavariable: $KEY
regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$
- focus-metavariable: $KEY
- patterns:
- pattern-either:
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: $KEY)
- pattern: |
UserDefaults.standard.set($VALUE, forKey: "$KEY")
- pattern: |
UserDefaults.standard.set($VALUE, forKey: $KEY)
- metavariable-regex:
metavariable: $VALUE
regex: (?i).*(api_key|apikey)$
- focus-metavariable: $VALUE
- patterns:
- pattern-either:
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: $KEY)
- pattern: |
UserDefaults.standard.set($VALUE, forKey: "$KEY")
- pattern: |
UserDefaults.standard.set($VALUE, forKey: $KEY)
- metavariable-regex:
metavariable: $KEY
regex: (?i).*(api_key|apikey)$
- focus-metavariable: $KEY
- patterns:
- pattern-either:
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: $KEY)
- pattern: |
UserDefaults.standard.set($VALUE, forKey: "$KEY")
- pattern: |
UserDefaults.standard.set($VALUE, forKey: $KEY)
- metavariable-regex:
metavariable: $VALUE
regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$
- focus-metavariable: $VALUE
- patterns:
- pattern-either:
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: $KEY)
- pattern: |
UserDefaults.standard.set($VALUE, forKey: "$KEY")
- pattern: |
UserDefaults.standard.set($VALUE, forKey: $KEY)
- metavariable-regex:
metavariable: $KEY
regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$
- focus-metavariable: $KEY
- patterns:
- pattern-either:
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: $KEY)
- pattern: |
UserDefaults.standard.set($VALUE, forKey: "$KEY")
- pattern: |
UserDefaults.standard.set($VALUE, forKey: $KEY)
- metavariable-regex:
metavariable: $VALUE
regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$
- focus-metavariable: $VALUE
- patterns:
- pattern-either:
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: "$KEY")
- pattern: |
UserDefaults.standard.set("$VALUE", forKey: $KEY)
- pattern: |
UserDefaults.standard.set($VALUE, forKey: "$KEY")
- pattern: |
UserDefaults.standard.set($VALUE, forKey: $KEY)
- metavariable-regex:
metavariable: $KEY
regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$
- focus-metavariable: $KEY
- id: java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request
message: Detected input from a HTTPServletRequest going into the environment variables
of an 'exec' command. Instead, call the command with user-supplied arguments
by using the overloaded method with one String array as the argument. `exec({"command",
"arg1", "arg2"})`.
languages:
- java
severity: ERROR
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: |
(HttpServletRequest $REQ)
- patterns:
- pattern-inside: |
(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);
...
for (javax.servlet.http.Cookie $COOKIE: $COOKIES) {
...
}
- pattern: |
$COOKIE.getValue(...)
pattern-sinks:
- patterns:
- pattern: (java.lang.Runtime $R).exec($CMD, $ENV_ARGS, ...);
- focus-metavariable: $ENV_ARGS
metadata:
category: security
technology:
- java
cwe:
- 'CWE-454: External Initialization of Trusted Variables or Data Stores'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: false
cwe2021-top25: false
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request
shortlink: https://sg.run/EJAB
semgrep.dev:
rule:
r_id: 70981
rv_id: 1409391
rule_id: nJULjy
version_id: LjTRL6W
url: https://semgrep.dev/playground/r/LjTRL6W/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request
origin: community
- patterns:
- pattern-either:
- pattern: |
provisioner "remote-exec" {
...
}
- pattern: |
provisioner "local-exec" {
...
}
- pattern-inside: |
resource "aws_instance" "..." {
...
}
id: terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec
message: Provisioners are a tool of last resort and should be avoided where possible.
Provisioner behavior cannot be mapped by Terraform as part of a plan, and execute
arbitrary shell commands by design.
languages:
- terraform
severity: WARNING
metadata:
category: security
owasp:
- A03:2021 - Injection
- A01:2017 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-77: Improper Neutralization of Special Elements used in a Command (''Command
Injection'')'
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
subcategory:
- audit
confidence: HIGH
likelihood: HIGH
impact: MEDIUM
technology:
- terraform
references:
- https://developer.hashicorp.com/terraform/language/resources/provisioners/remote-exec
- https://developer.hashicorp.com/terraform/language/resources/provisioners/local-exec
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
- Other
source: https://semgrep.dev/r/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec
shortlink: https://sg.run/7EjQ
semgrep.dev:
rule:
r_id: 70982
rv_id: 1263736
rule_id: EwUxO1
version_id: bZT53j1
url: https://semgrep.dev/playground/r/bZT53j1/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec
origin: community
- id: terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy
metadata:
category: security
subcategory:
- audit
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
technology:
- terraform
- aws
owasp:
- A05:2017 - Sensitive Data Exposure
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
cwe:
- 'CWE-1220: Insufficient Granularity of Access Control'
references:
- https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-amazon-web-services#configuring-the-role-and-trust-policy
- https://dagrz.com/writing/aws-security/hacking-github-aws-oidc/
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy
shortlink: https://sg.run/LWlY
semgrep.dev:
rule:
r_id: 70983
rv_id: 1263748
rule_id: 7KU3dr
version_id: 7ZTE346
url: https://semgrep.dev/playground/r/7ZTE346/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy
origin: community
message: '`$POLICY` is missing a `condition` block which scopes users of this policy
to specific GitHub repositories. Without this, `$POLICY` is open to all users
on GitHub. Add a `condition` block on the variable `token.actions.githubusercontent.com:sub`
which scopes it to prevent this.'
languages:
- hcl
severity: WARNING
match:
where:
- metavariable: $IDENTIFIER
regex: .*oidc-provider/token\.actions\.githubusercontent\.com
all:
- inside: |
data "aws_iam_policy_document" $POLICY {
...
}
- |
statement {
...
principals {
...
type = "Federated"
identifiers = [..., $IDENTIFIER, ...]
}
}
- not: |
statement {
...
condition {
...
variable = "token.actions.githubusercontent.com:sub"
}
}
- id: clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe
languages:
- clojure
severity: ERROR
metadata:
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
asvs:
section: V5 Validation, Sanitization and Encoding
control_id: 5.5.2 Insecue XML Deserialization
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention
version: '4'
references:
- https://semgrep.dev/blog/2022/xml-security-in-java
- https://semgrep.dev/docs/cheat-sheets/java-xxe/
- https://xerces.apache.org/xerces2-j/features.html
source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/xxe-clojure-xml/xxe-clojure-xml.yml
category: security
technology:
- clojure
- xml
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe
shortlink: https://sg.run/v7An
semgrep.dev:
rule:
r_id: 71533
rv_id: 1262608
rule_id: bwU3Gj
version_id: WrTqKyD
url: https://semgrep.dev/playground/r/WrTqKyD/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe
origin: community
message: DOCTYPE declarations are enabled for javax.xml.parsers.SAXParserFactory.
Without prohibiting external entity declarations, this is vulnerable to XML external
entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl"
to true. Alternatively, allow DOCTYPE declarations and only prohibit external
entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities"
and "http://xml.org/sax/features/external-parameter-entities" to false.
patterns:
- pattern-inside: |
(ns ... (:require [clojure.xml :as ...]))
...
- pattern-either:
- pattern-inside: |
(def ... ... ( ... ))
- pattern-inside: |
(defn ... ... ( ... ))
- pattern-either:
- pattern: (clojure.xml/parse $INPUT)
- patterns:
- pattern-inside: |
(doto (javax.xml.parsers.SAXParserFactory/newInstance) ...)
- pattern: (.setFeature "http://apache.org/xml/features/disallow-doctype-decl"
false)
- pattern-not-inside: |
(doto (javax.xml.parsers.SAXParserFactory/newInstance)
...
(.setFeature "http://xml.org/sax/features/external-general-entities" false)
...
(.setFeature "http://xml.org/sax/features/external-parameter-entities" false)
...)
- pattern-not-inside: |
(doto (javax.xml.parsers.SAXParserFactory/newInstance)
...
(.setFeature "http://xml.org/sax/features/external-parameter-entities" false)
...
(.setFeature "http://xml.org/sax/features/external-general-entities" false)
...)
- id: clojure.lang.security.use-of-sha1.use-of-sha1
languages:
- clojure
severity: WARNING
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
collision resistant and is therefore not suitable as a cryptographic signature.
Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function
applications.
metadata:
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
technology:
- clojure
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
- 'CWE-328: Use of Weak Hash'
category: security
subcategory:
- vuln
confidence: HIGH
likelihood: MEDIUM
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/clojure.lang.security.use-of-sha1.use-of-sha1
shortlink: https://sg.run/dvwX
semgrep.dev:
rule:
r_id: 71534
rv_id: 1262610
rule_id: NbUy12
version_id: K3TKk7E
url: https://semgrep.dev/playground/r/K3TKk7E/clojure.lang.security.use-of-sha1.use-of-sha1
origin: community
patterns:
- pattern-either:
- pattern: (MessageDigest/getInstance $ALGO)
- pattern: (java.security.MessageDigest/getInstance $ALGO)
- metavariable-regex:
metavariable: $ALGO
regex: (((org\.apache\.commons\.codec\.digest\.)?MessageDigestAlgorithms/)?"?(SHA-1|SHA1)"?)
- id: generic.visualforce.security.ncino.html.usesriforcdns.use-SRI-for-CDNs
languages:
- generic
severity: WARNING
message: 'Consuming CDNs without including a SubResource Integrity (SRI) can expose
your application and its users to compromised code. SRIs allow you to consume
specific versions of content where if even a single byte is compromised, the resource
will not be loaded. Add an integrity attribute to your <script> and <link> tags
pointing to CDN content to ensure the resources have not been compromised. A crossorigin
attribute should also be added. For a more thorough explanation along with explicit
instructions on remediating, follow the directions from Mozilla here: https://developer.mozilla.org/en-US/blog/securing-cdn-using-sri-why-how/'
metadata:
cwe:
- 'CWE-346: Origin Validation Error'
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe2020-top25': true
cwe2021-top25': true
cwe2022-top25': true
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
category: security
subcategory:
- vuln
technology:
- salesforce
- visualforce
references:
- https://cwe.mitre.org/data/definitions/352.html
- https://developer.mozilla.org/en-US/blog/securing-cdn-using-sri-why-how/
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/generic.visualforce.security.ncino.html.usesriforcdns.use-SRI-for-CDNs
shortlink: https://sg.run/1pXb
semgrep.dev:
rule:
r_id: 72422
rv_id: 1262905
rule_id: AbU20Y
version_id: 5PTo1or
url: https://semgrep.dev/playground/r/5PTo1or/generic.visualforce.security.ncino.html.usesriforcdns.use-SRI-for-CDNs
origin: community
patterns:
- pattern-either:
- pattern: <link...href="$URL..."...>
- pattern: <script...src="$URL..."...>
- metavariable-regex:
metavariable: $URL
regex: http[A-Za-z0-9\/\.\-\:]
- pattern-not: <script...integrity="..."...src="..."...>
- pattern-not: <script...src="..."...integrity="..."...>
- pattern-not: <link...integrity="..."...href="..."...>
- pattern-not: <link...href="..."...integrity="..."...>
paths:
include:
- '*.component'
- '*.page'
- id: generic.visualforce.security.ncino.vf.xssfromunescapedurlparam.xss-from-unescaped-url-param
languages:
- generic
severity: ERROR
message: To remediate this issue, ensure that all URL parameters are properly escaped
before including them in scripts. Please update your code to use either the JSENCODE
method to escape URL parameters or the escape="true" attribute on <apex:outputText>
tags. Passing URL parameters directly into scripts and DOM sinks creates an opportunity
for Cross-Site Scripting attacks. Cross-Site Scripting (XSS) attacks are a type
of injection, in which malicious scripts are injected into otherwise benign and
trusted websites. To remediate this issue, ensure that all URL parameters are
properly escaped before including them in scripts.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://developer.salesforce.com/docs/atlas.en-us.apexcode.meta/apexcode/pages_security_tips_xss.htm
category: security
subcategory:
- vuln
technology:
- salesforce
- visualforce
cwe2022-top25: true
cwe2021-top25: true
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/generic.visualforce.security.ncino.vf.xssfromunescapedurlparam.xss-from-unescaped-url-param
shortlink: https://sg.run/9bGk
semgrep.dev:
rule:
r_id: 72423
rv_id: 1262906
rule_id: BYUAJ2
version_id: GxTkekB
url: https://semgrep.dev/playground/r/GxTkekB/generic.visualforce.security.ncino.vf.xssfromunescapedurlparam.xss-from-unescaped-url-param
origin: community
patterns:
- pattern-either:
- pattern: <apex:outputText...escape="false"...value="{!...CurrentPage.parameters.$URL_PARAM}".../>
- pattern: <apex:outputText...value="{!...CurrentPage.parameters.$URL_PARAM}"...escape="false".../>
- pattern: <script>...'{!...CurrentPage.parameters.$URL_PARAM}'...</script>
- pattern-not: <script>...'{!...JSENCODE(...CurrentPage.parameters.$URL_PARAM})'...</script>
paths:
include:
- '*.component'
- '*.page'
- id: generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute
languages:
- generic
severity: INFO
message: Visualforce Pages must have the cspHeader attribute set to true. This attribute
is available in API version 55 or higher.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://help.salesforce.com/s/articleView?id=sf.csp_trusted_sites.htm&type=5
category: security
subcategory:
- vuln
technology:
- salesforce
- visualforce
cwe2022-top25: true
cwe2021-top25: true
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute
shortlink: https://sg.run/yoj8
semgrep.dev:
rule:
r_id: 72424
rv_id: 1262907
rule_id: DbUj7d
version_id: RGT0L0r
url: https://semgrep.dev/playground/r/RGT0L0r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute
origin: community
patterns:
- pattern: <apex:page...>...</apex:page>
- pattern-not: <apex:page...cspHeader="true"...>...</apex:page>
- pattern-not: <apex:page...>...<!--deprecated-->...</apex:page>
- pattern-not: <apex:page...>...<!-- deprecated -->...</apex:page>
paths:
include:
- '*.page'
- id: generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version
languages:
- generic
severity: WARNING
message: Visualforce Pages must use API version 55 or higher for required use of
the cspHeader attribute set to true.
metadata:
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://developer.salesforce.com/docs/atlas.en-us.api_meta.meta/api_meta/meta_pages.htm
category: security
subcategory:
- vuln
technology:
- salesforce
- visualforce
cwe2022-top25: true
cwe2021-top25: true
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version
shortlink: https://sg.run/rWr6
semgrep.dev:
rule:
r_id: 72425
rv_id: 1262908
rule_id: WAUwJW
version_id: A8Tgdgn
url: https://semgrep.dev/playground/r/A8Tgdgn/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version
origin: community
patterns:
- pattern-inside: <apiVersion.../apiVersion>
- pattern-either:
- pattern-regex: '[>][0-9].[0-9][<]'
- pattern-regex: '[>][1-4][0-9].[0-9][<]'
- pattern-regex: '[>][5][0-4].[0-9][<]'
paths:
include:
- '*.page-meta.xml'
- id: python.django.security.hashids-with-django-secret.hashids-with-django-secret
languages:
- python
message: The Django secret key is used as salt in HashIDs. The HashID mechanism
is not secure. By observing sufficient HashIDs, the salt used to construct them
can be recovered. This means the Django secret key can be obtained by attackers,
through the HashIDs.
metadata:
category: security
subcategory:
- vuln
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- "A02:2021 \u2013 Cryptographic Failures"
references:
- https://docs.djangoproject.com/en/4.2/ref/settings/#std-setting-SECRET_KEY
- http://carnage.github.io/2015/08/cryptanalysis-of-hashids
technology:
- django
likelihood: LOW
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.django.security.hashids-with-django-secret.hashids-with-django-secret
shortlink: https://sg.run/bxeZ
semgrep.dev:
rule:
r_id: 72426
rv_id: 946163
rule_id: 0oUXqy
version_id: 0bT15nn
url: https://semgrep.dev/playground/r/0bT15nn/python.django.security.hashids-with-django-secret.hashids-with-django-secret
origin: community
pattern-either:
- pattern: hashids.Hashids(..., salt=django.conf.settings.SECRET_KEY, ...)
- pattern: hashids.Hashids(django.conf.settings.SECRET_KEY, ...)
severity: ERROR
- id: python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret
languages:
- python
message: The Flask secret key is used as salt in HashIDs. The HashID mechanism is
not secure. By observing sufficient HashIDs, the salt used to construct them can
be recovered. This means the Flask secret key can be obtained by attackers, through
the HashIDs.
metadata:
category: security
subcategory:
- vuln
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- "A02:2021 \u2013 Cryptographic Failures"
references:
- https://flask.palletsprojects.com/en/2.2.x/config/#SECRET_KEY
- http://carnage.github.io/2015/08/cryptanalysis-of-hashids
technology:
- flask
likelihood: LOW
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret
shortlink: https://sg.run/N0Rx
semgrep.dev:
rule:
r_id: 72427
rv_id: 946220
rule_id: KxUX3z
version_id: 0bT15Px
url: https://semgrep.dev/playground/r/0bT15Px/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret
origin: community
pattern-either:
- pattern: hashids.Hashids(..., salt=flask.current_app.config['SECRET_KEY'], ...)
- pattern: hashids.Hashids(flask.current_app.config['SECRET_KEY'], ...)
- patterns:
- pattern-inside: |
$APP = flask.Flask(...)
...
- pattern-either:
- pattern: hashids.Hashids(..., salt=$APP.config['SECRET_KEY'], ...)
- pattern: hashids.Hashids($APP.config['SECRET_KEY'], ...)
severity: ERROR
- id: python.lang.security.use-defused-xml-parse.use-defused-xml-parse
metadata:
owasp:
- A04:2017 - XML External Entities (XXE)
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
cwe:
- 'CWE-611: Improper Restriction of XML External Entity Reference'
references:
- https://docs.python.org/3/library/xml.html
- https://github.com/tiran/defusedxml
- https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing
category: security
technology:
- python
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- XML Injection
source: https://semgrep.dev/r/python.lang.security.use-defused-xml-parse.use-defused-xml-parse
shortlink: https://sg.run/n3jG
semgrep.dev:
rule:
r_id: 72436
rv_id: 1263541
rule_id: X5Uqnx
version_id: vdT06ER
url: https://semgrep.dev/playground/r/vdT06ER/python.lang.security.use-defused-xml-parse.use-defused-xml-parse
origin: community
message: The native Python `xml` library is vulnerable to XML External Entity (XXE)
attacks. These attacks can leak confidential data and "XML bombs" can cause denial
of service. Do not use this library to parse untrusted input. Instead the Python
documentation recommends using `defusedxml`.
languages:
- python
severity: ERROR
patterns:
- pattern: xml.etree.ElementTree.parse($...ARGS)
- pattern-not: xml.etree.ElementTree.parse("...")
fix: defusedxml.etree.ElementTree.parse($...ARGS)
- id: php.lang.security.tainted-exec.tainted-exec
mode: taint
pattern-sources:
- pattern: $_REQUEST
- pattern: $_GET
- pattern: $_POST
- pattern: $_COOKIE
pattern-sinks:
- pattern: exec(...)
- pattern: system(...)
- pattern: popen(...)
- pattern: passthru(...)
- pattern: shell_exec(...)
- pattern: pcntl_exec(...)
- pattern: proc_open(...)
pattern-sanitizers:
- pattern: escapeshellarg(...)
message: Executing non-constant commands. This can lead to command injection. You
should use `escapeshellarg()` when using command.
metadata:
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
references:
- https://www.stackhawk.com/blog/php-command-injection/
- https://brightsec.com/blog/code-injection-php/
- https://www.acunetix.com/websitesecurity/php-security-2/
category: security
technology:
- php
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
cwe2022-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/php.lang.security.tainted-exec.tainted-exec
shortlink: https://sg.run/JAkP
semgrep.dev:
rule:
r_id: 73146
rv_id: 1263300
rule_id: 9AUw06
version_id: BjTkZ4y
url: https://semgrep.dev/playground/r/BjTkZ4y/php.lang.security.tainted-exec.tainted-exec
origin: community
languages:
- php
severity: ERROR
- id: php.lang.security.injection.tainted-session.tainted-session
severity: WARNING
message: Session key based on user input risks session poisoning. The user can determine
the key used for the session, and thus write any session variable. Session variables
are typically trusted to be set only by the application, and manipulating the
session can result in access control issues.
metadata:
technology:
- php
category: security
cwe:
- 'CWE-284: Improper Access Control'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://en.wikipedia.org/wiki/Session_poisoning
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/php.lang.security.injection.tainted-session.tainted-session
shortlink: https://sg.run/bxNp
semgrep.dev:
rule:
r_id: 73470
rv_id: 1263289
rule_id: 4bUdoP
version_id: 8KT5rPE
url: https://semgrep.dev/playground/r/8KT5rPE/php.lang.security.injection.tainted-session.tainted-session
origin: community
languages:
- php
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: $_GET
- pattern: $_POST
- pattern: $_COOKIE
- pattern: $_REQUEST
pattern-sanitizers:
- patterns:
- pattern-either:
- pattern: $A . $B
- pattern: bin2hex(...)
- pattern: crc32(...)
- pattern: crypt(...)
- pattern: filter_input(...)
- pattern: filter_var(...)
- pattern: hash(...)
- pattern: md5(...)
- pattern: preg_filter(...)
- pattern: preg_grep(...)
- pattern: preg_match_all(...)
- pattern: sha1(...)
- pattern: sprintf(...)
- pattern: str_contains(...)
- pattern: str_ends_with(...)
- pattern: str_starts_with(...)
- pattern: strcasecmp(...)
- pattern: strchr(...)
- pattern: stripos(...)
- pattern: stristr(...)
- pattern: strnatcasecmp(...)
- pattern: strnatcmp(...)
- pattern: strncmp(...)
- pattern: strpbrk(...)
- pattern: strpos(...)
- pattern: strripos(...)
- pattern: strrpos(...)
- pattern: strspn(...)
- pattern: strstr(...)
- pattern: strtok(...)
- pattern: substr_compare(...)
- pattern: substr_count(...)
- pattern: vsprintf(...)
pattern-sinks:
- patterns:
- pattern-inside: $_SESSION[$KEY] = $VAL;
- pattern: $KEY
- id: yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions
patterns:
- pattern: |
"*"
- pattern-inside: |
resources: $A
...
- pattern-inside: |
verbs: $A
...
- pattern-inside: |
- apiGroups: [""]
...
- pattern-inside: |
apiVersion: rbac.authorization.k8s.io/v1
...
- pattern-inside: |
kind: ClusterRole
...
message: 'Semgrep detected a Kubernetes core API ClusterRole with excessive permissions.
Attaching excessive permissions to a ClusterRole associated with the core namespace
allows the V1 API to perform arbitrary actions on arbitrary resources attached
to the cluster. Prefer explicit allowlists of verbs/resources when configuring
the core API namespace. '
languages:
- yaml
severity: WARNING
metadata:
cwe:
- 'CWE-269: Improper Privilege Management'
owasp:
- A05:2021 - Security Misconfiguration
- A06:2017 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://kubernetes.io/docs/reference/access-authn-authz/rbac/#role-and-clusterrole
- https://kubernetes.io/docs/concepts/security/rbac-good-practices/#general-good-practice
- https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#api-groups
category: security
technology:
- kubernetes
cwe2021-top25: false
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions
shortlink: https://sg.run/x6Dz
semgrep.dev:
rule:
r_id: 73474
rv_id: 1263935
rule_id: GdUR2A
version_id: 9lT4bw7
url: https://semgrep.dev/playground/r/9lT4bw7/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions
origin: community
- id: python.fastapi.security.wildcard-cors.wildcard-cors
languages:
- python
message: CORS policy allows any origin (using wildcard '*'). This is insecure and
should be avoided.
mode: taint
pattern-sources:
- pattern: '[..., "*", ...]'
pattern-sinks:
- patterns:
- pattern: |
$APP.add_middleware(
CORSMiddleware,
allow_origins=$ORIGIN,
...);
- focus-metavariable: $ORIGIN
severity: WARNING
metadata:
cwe:
- 'CWE-942: Permissive Cross-domain Policy with Untrusted Domains'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
category: security
technology:
- python
- fastapi
references:
- https://owasp.org/Top10/A05_2021-Security_Misconfiguration
- https://cwe.mitre.org/data/definitions/942.html
likelihood: HIGH
impact: LOW
confidence: MEDIUM
vulnerability_class:
- Configuration
subcategory:
- vuln
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/python.fastapi.security.wildcard-cors.wildcard-cors
shortlink: https://sg.run/KxApY
semgrep.dev:
rule:
r_id: 112311
rv_id: 1263413
rule_id: lBU4JQ3
version_id: A8Tgd1R
url: https://semgrep.dev/playground/r/A8Tgd1R/python.fastapi.security.wildcard-cors.wildcard-cors
origin: community
- id: javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify
message: Detected the decoding of a JWT token without a verify step. JWT tokens
must be verified before use, otherwise the token's integrity is unknown. This
means a malicious actor could forge a JWT token with any claims. Set 'verify'
to `true` before using the token.
severity: ERROR
metadata:
owasp:
- A05:2021 - Security Misconfiguration
- A07:2021 - Identification and Authentication Failures
- A02:2025 - Security Misconfiguration
- A07:2025 - Authentication Failures
cwe:
- 'CWE-287: Improper Authentication'
- 'CWE-345: Insufficient Verification of Data Authenticity'
- 'CWE-347: Improper Verification of Cryptographic Signature'
category: security
subcategory:
- vuln
technology:
- jwt-simple
- jwt
confidence: HIGH
likelihood: MEDIUM
impact: HIGH
references:
- https://www.npmjs.com/package/jwt-simple
- https://cwe.mitre.org/data/definitions/287
- https://cwe.mitre.org/data/definitions/345
- https://cwe.mitre.org/data/definitions/347
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
- Improper Authentication
source: https://semgrep.dev/r/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify
shortlink: https://sg.run/zdjod
semgrep.dev:
rule:
r_id: 120561
rv_id: 1263191
rule_id: r6UyNLy
version_id: 3ZT4Xxv
url: https://semgrep.dev/playground/r/3ZT4Xxv/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify
origin: community
languages:
- javascript
- typescript
patterns:
- pattern-inside: |
$JWT = require('jwt-simple');
...
- pattern: $JWT.decode($TOKEN, $SECRET, $NOVERIFY, ...)
- metavariable-pattern:
metavariable: $NOVERIFY
patterns:
- pattern-either:
- pattern: |
true
- pattern: |
"..."
- id: php.lang.security.injection.printed-request.printed-request
mode: taint
message: '`Printing user input risks cross-site scripting vulnerability. You should
use `htmlentities()` when showing data to users.'
languages:
- php
severity: ERROR
pattern-sources:
- pattern: $_REQUEST
- pattern: $_GET
- pattern: $_POST
pattern-sinks:
- pattern: print($...VARS);
pattern-sanitizers:
- pattern: htmlentities(...)
- pattern: htmlspecialchars(...)
- pattern: strip_tags(...)
- pattern: isset(...)
- pattern: empty(...)
- pattern: esc_html(...)
- pattern: esc_attr(...)
- pattern: wp_kses(...)
- pattern: e(...)
- pattern: twig_escape_filter(...)
- pattern: xss_clean(...)
- pattern: html_escape(...)
- pattern: Html::escape(...)
- pattern: Xss::filter(...)
- pattern: escapeHtml(...)
- pattern: escapeHtml(...)
- pattern: escapeHtmlAttr(...)
fix: print(htmlentities($...VARS));
metadata:
technology:
- php
cwe:
- 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site
Scripting'')'
owasp:
- A07:2017 - Cross-Site Scripting (XSS)
- A03:2021 - Injection
- A05:2025 - Injection
category: security
references:
- https://www.php.net/manual/en/function.htmlentities.php
- https://www.php.net/manual/en/reserved.variables.request.php
- https://www.php.net/manual/en/reserved.variables.post.php
- https://www.php.net/manual/en/reserved.variables.get.php
- https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cross-Site-Scripting (XSS)
source: https://semgrep.dev/r/php.lang.security.injection.printed-request.printed-request
shortlink: https://sg.run/QrxEJ
semgrep.dev:
rule:
r_id: 128886
rv_id: 1263284
rule_id: KxUvRBw
version_id: ZRTKAk4
url: https://semgrep.dev/playground/r/ZRTKAk4/php.lang.security.injection.printed-request.printed-request
origin: community
- id: go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone
patterns:
- pattern-inside: |
&sessions.Options{
...,
SameSite: http.SameSiteNoneMode,
...,
}
- pattern: |
&sessions.Options{
...,
}
message: Found SameSiteNoneMode setting in Gorilla session options. Consider setting
SameSite to Lax, Strict or Default for enhanced security.
metadata:
cwe:
- 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute'
owasp:
- A05:2021 - Security Misconfiguration
- A02:2025 - Security Misconfiguration
references:
- https://pkg.go.dev/github.com/gorilla/sessions#Options
category: security
technology:
- gorilla
confidence: MEDIUM
subcategory:
- audit
likelihood: LOW
impact: LOW
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cookie Security
source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone
shortlink: https://sg.run/x8Nwj
semgrep.dev:
rule:
r_id: 133074
rv_id: 1262913
rule_id: YGUpGd4
version_id: K3TKkKB
url: https://semgrep.dev/playground/r/K3TKkKB/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone
origin: community
fix-regex:
regex: (SameSite\s*:\s+)http.SameSiteNoneMode
replacement: \1http.SameSiteDefaultMode
severity: WARNING
languages:
- go
- id: solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx
languages:
- solidity
message: Missing check for 'from' and 'to' being the same before updating balances
could lead to incorrect balance manipulation on self-transfers. Include a check
to ensure 'from' and 'to' are not the same before updating balances to prevent
balance manipulation during self-transfers.
severity: ERROR
metadata:
category: security
technology:
- blockchain
- solidity
cwe: 'CWE-682: Incorrect Calculation'
subcategory:
- vuln
confidence: HIGH
likelihood: HIGH
impact: HIGH
owasp:
- A7:2021 Identification and Authentication Failures
references:
- https://blog.verichains.io/p/miner-project-attacked-by-vulnerabilities
- https://x.com/shoucccc/status/1757777764646859121
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx
shortlink: https://sg.run/Or6X7
semgrep.dev:
rule:
r_id: 133075
rv_id: 946620
rule_id: 6JUv7Nz
version_id: A8TJzYz
url: https://semgrep.dev/playground/r/A8TJzYz/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx
origin: community
patterns:
- pattern-either:
- pattern: |
_balances[$FROM] = $FROM_BALANCE - value;
- pattern: |
_balances[$TO] = $TO_BALANCE + value;
- pattern-not-inside: |
if ($FROM != $TO) {
...
_balances[$FROM] = $FROM_BALANCE - value;
...
_balances[$TO] = $TO_BALANCE + value;
...
}
- pattern-inside: |
function _update(address $FROM, address $TO, uint256 value, bool mint) internal virtual {
...
}
- id: yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication
languages:
- yaml
message: Basic authentication is considered weak and should be avoided. Use a different
authentication scheme, such of OAuth2, OpenID Connect, or mTLS.
severity: ERROR
patterns:
- pattern-inside: |
openapi: $VERSION
...
components:
...
securitySchemes:
...
$SCHEME:
...
- metavariable-regex:
metavariable: $VERSION
regex: 3.*
- pattern: |
type: http
...
scheme: basic
metadata:
category: security
subcategory:
- vuln
technology:
- openapi
likelihood: MEDIUM
impact: HIGH
confidence: HIGH
cwe: 'CWE-287: Improper Authentication'
owasp:
- A04:2021 Insecure Design
- A07:2021 Identification and Authentication Failures
references:
- https://cwe.mitre.org/data/definitions/287.html
- https://owasp.org/Top10/A04_2021-Insecure_Design/
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication
shortlink: https://sg.run/v8wNW
semgrep.dev:
rule:
r_id: 133077
rv_id: 947072
rule_id: zdUKgEX
version_id: 0bT1ErG
url: https://semgrep.dev/playground/r/0bT1ErG/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication
origin: community
- id: python.twilio.security.twiml-injection.twiml-injection
languages:
- python
severity: WARNING
message: Using non-constant TwiML (Twilio Markup Language) argument when creating
a Twilio conversation could allow the injection of additional TwiML commands
metadata:
cwe:
- 'CWE-91: XML Injection'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- python
- twilio
- twiml
confidence: MEDIUM
likelihood: HIGH
impact: MEDIUM
subcategory:
- vuln
references:
- https://codeberg.org/fennix/funjection
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/python.twilio.security.twiml-injection.twiml-injection
shortlink: https://sg.run/GdEEy
semgrep.dev:
rule:
r_id: 134692
rv_id: 1263580
rule_id: oqUgjj2
version_id: kbTzGp1
url: https://semgrep.dev/playground/r/kbTzGp1/python.twilio.security.twiml-injection.twiml-injection
origin: community
mode: taint
pattern-sources:
- pattern: |
f"..."
- pattern: |
"..." % ...
- pattern: |
"...".format(...)
- patterns:
- pattern: $ARG
- pattern-inside: |
def $F(..., $ARG, ...):
...
pattern-sanitizers:
- pattern: xml.sax.saxutils.escape(...)
- pattern: html.escape(...)
pattern-sinks:
- patterns:
- pattern: |
$CLIENT.calls.create(..., twiml=$SINK, ...)
- focus-metavariable: $SINK
- id: kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded
message: A secret is hard-coded in the application. Secrets stored in source code,
such as credentials, identifiers, and other types of sensitive data, can be leaked
and used by internal or external malicious actors. It is recommended to rotate
the secret and retrieve them from a secure secret vault or Hardware Security Module
(HSM), alternatively environment variables can be used if allowed by your company
policy.
severity: WARNING
metadata:
likelihood: LOW
impact: HIGH
confidence: MEDIUM
category: security
subcategory:
- vuln
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
cwe2020-top25: true
cwe2021-top25: true
cwe2022-top25: true
owasp:
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
references:
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
technology:
- secrets
vulnerability_class:
- Hard-coded Secrets
source_rule_url: https://semgrep.dev/playground/r/d8Ur5BA/achufistov6_personal_org.build-gradle-password-hardcoded
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded
shortlink: https://sg.run/qN29x
semgrep.dev:
rule:
r_id: 137856
rv_id: 1263257
rule_id: ReUD6Kg
version_id: DkTRbLX
url: https://semgrep.dev/playground/r/DkTRbLX/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded
origin: community
languages:
- kotlin
options:
symbolic_propagation: true
patterns:
- pattern-either:
- pattern: '$PASS = env[...] ?: $VALUE'
- metavariable-regex:
metavariable: $PASS
regex: (password|pass|passwd|loginPassword)
- metavariable-pattern:
language: generic
metavariable: $VALUE
patterns:
- pattern-either:
- pattern-regex: ^[A-Za-z0-9/+=]+$
paths:
include:
- '*build.gradle.kts'
- id: php.lang.security.injection.tainted-callable.tainted-callable
severity: WARNING
message: Callable based on user input risks remote code execution.
metadata:
technology:
- php
category: security
cwe:
- 'CWE-94: Improper Control of Generation of Code (''Code Injection'')'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://www.php.net/manual/en/language.types.callable.php
subcategory:
- vuln
impact: HIGH
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Code Injection
source: https://semgrep.dev/r/php.lang.security.injection.tainted-callable.tainted-callable
shortlink: https://sg.run/YGb33
semgrep.dev:
rule:
r_id: 141958
rv_id: 1263285
rule_id: 0oULBKK
version_id: nWT2L5x
url: https://semgrep.dev/playground/r/nWT2L5x/php.lang.security.injection.tainted-callable.tainted-callable
origin: community
languages:
- php
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: $_GET
- pattern: $_POST
- pattern: $_COOKIE
- pattern: $_REQUEST
- pattern: file_get_contents('php://input')
pattern-sinks:
- patterns:
- pattern: $CALLABLE
- pattern-either:
- pattern-inside: $ARRAYITERATOR->uasort($CALLABLE)
- pattern-inside: $ARRAYITERATOR->uksort($CALLABLE)
- pattern-inside: $EVENTHTTP->setCallback($CALLABLE, ...)
- pattern-inside: $EVENTHTTPCONNECTION->setCloseCallback($CALLABLE, ...)
- pattern-inside: $EVLOOP->fork($CALLABLE, ...)
- pattern-inside: $EVLOOP->idle($CALLABLE, ...)
- pattern-inside: $EVLOOP->prepare($CALLABLE, ...)
- pattern-inside: $EVWATCHER->setCallback($CALLABLE)
- pattern-inside: $GEARMANCLIENT->setClientCallback($CALLABLE)
- pattern-inside: $GEARMANCLIENT->setCompleteCallback($CALLABLE)
- pattern-inside: $GEARMANCLIENT->setCreatedCallback($CALLABLE)
- pattern-inside: $GEARMANCLIENT->setDataCallback($CALLABLE)
- pattern-inside: $GEARMANCLIENT->setExceptionCallback($CALLABLE)
- pattern-inside: $GEARMANCLIENT->setFailCallback($CALLABLE)
- pattern-inside: $GEARMANCLIENT->setStatusCallback($CALLABLE)
- pattern-inside: $GEARMANCLIENT->setWarningCallback($CALLABLE)
- pattern-inside: $GEARMANCLIENT->setWorkloadCallback($CALLABLE)
- pattern-inside: $IMAGICK->setProgressMonitor($CALLABLE)
- pattern-inside: $OAUTHPROVIDER->consumerHandler($CALLABLE)
- pattern-inside: $OAUTHPROVIDER->tokenHandler($CALLABLE)
- pattern-inside: $PDO->sqliteCreateCollation($NAME, $CALLABLE)
- pattern-inside: $PDOSTATEMENT->fetchAll(PDO::FETCH_FUNC, $CALLABLE)
- pattern-inside: $SQLITE3->createCollation($NAME, $CALLABLE)
- pattern-inside: $SQLITE3->setAuthorizer($CALLABLE)
- pattern-inside: $ZIPARCHIVE->registerCancelCallback($CALLABLE)
- pattern-inside: $ZIPARCHIVE->registerProgressCallback($RATE, $CALLABLE)
- pattern-inside: $ZMQDEVICE->setIdleCallback($CALLABLE, ...)
- pattern-inside: $ZMQDEVICE->setTimerCallback($CALLABLE, ...)
- pattern-inside: apcu_entry($KEY, $CALLABLE, ...)
- pattern-inside: array_filter($ARRAY, $CALLABLE, ...)
- pattern-inside: array_map($CALLABLE, ...)
- pattern-inside: array_reduce($ARRAY, $CALLABLE, ...)
- pattern-inside: array_walk_recursive($ARRAY, $CALLABLE, ...)
- pattern-inside: array_walk($ARRAY, $CALLABLE, ...)
- pattern-inside: call_user_func_array($CALLABLE, ...)
- pattern-inside: call_user_func($CALLABLE, ...)
- pattern-inside: Closure::fromCallable($CALLABLE)
- pattern-inside: createCollation($NAME, $CALLABLE)
- pattern-inside: eio_grp($CALLABLE, ...)
- pattern-inside: eio_nop($PRI, $CALLABLE, ...)
- pattern-inside: eio_sync($PRI, $CALLABLE, ...)
- pattern-inside: EvPrepare::createStopped($CALLABLE, ...)
- pattern-inside: fann_set_callback($ANN, $CALLABLE)
- pattern-inside: fdf_enum_values($FDF_DOCUMENT, $CALLABLE, ...)
- pattern-inside: forward_static_call_array($CALLABLE, ...)
- pattern-inside: forward_static_call($CALLABLE, ...)
- pattern-inside: header_register_callback($CALLABLE)
- pattern-inside: ibase_set_event_handler($CALLABLE, ...)
- pattern-inside: IntlChar::enumCharTypes($CALLABLE)
- pattern-inside: iterator_apply($ITERATOR, $CALLABLE)
- pattern-inside: ldap_set_rebind_proc($LDAP, $CALLABLE)
- pattern-inside: libxml_set_external_entity_loader($CALLABLE, ...)
- pattern-inside: new CallbackFilterIterator($ITERATOR, $CALLABLE)
- pattern-inside: new EvCheck($CALLABLE, ...)
- pattern-inside: new EventHttpRequest($CALLABLE, ...)
- pattern-inside: new EvFork($CALLABLE, ...)
- pattern-inside: new EvIdle($CALLABLE, ...)
- pattern-inside: new Fiber($CALLABLE)
- pattern-inside: new Memcached($PERSISTENT_ID, $CALLABLE, ...)
- pattern-inside: new RecursiveCallbackFilterIterator($ITERATOR, $CALLABLE)
- pattern-inside: new Zookeeper($HOST, $CALLABLE, ...)
- pattern-inside: ob_start($CALLABLE, ...)
- pattern-inside: oci_register_taf_callback($CONNECTION, $CALLABLE)
- pattern-inside: readline_callback_handler_install($PROMPT, $CALLABLE)
- pattern-inside: readline_completion_function($CALLABLE)
- pattern-inside: register_shutdown_function($CALLABLE, ...)
- pattern-inside: register_tick_function($CALLABLE, ...)
- pattern-inside: rnp_ffi_set_pass_provider($FFI, $CALLABLE)
- pattern-inside: sapi_windows_set_ctrl_handler($CALLABLE, ...)
- pattern-inside: set_error_handler($CALLABLE, ...)
- pattern-inside: set_exception_handler($CALLABLE)
- pattern-inside: setAuthorizer($CALLABLE)
- pattern-inside: spl_autoload_register($CALLABLE, ...)
- pattern-inside: uasort($ARRAY, $CALLABLE)
- pattern-inside: uksort($ARRAY, $CALLABLE)
- pattern-inside: usort($ARRAY, $CALLABLE)
- pattern-inside: xml_set_character_data_handler($PARSER, $CALLABLE)
- pattern-inside: xml_set_default_handler($PARSER, $CALLABLE)
- pattern-inside: xml_set_element_handler($PARSER, $CALLABLE, $CALLABLE)
- pattern-inside: xml_set_notation_decl_handler($PARSER, $CALLABLE)
- pattern-inside: Yar_Concurrent_Client::loop($CALLABLE, ...)
- id: javascript.node-crypto.security.aead-no-final.aead-no-final
message: The 'final' call of a Decipher object checks the authentication tag in
a mode for authenticated encryption. Failing to call 'final' will invalidate all
integrity guarantees of the released ciphertext.
metadata:
cwe:
- 'CWE-310: CWE CATEGORY: Cryptographic Issues'
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
category: security
subcategory:
- vuln
technology:
- node-crypto
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
references:
- https://nodejs.org/api/crypto.html#deciphersetauthtagbuffer-encoding
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures/
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/javascript.node-crypto.security.aead-no-final.aead-no-final
shortlink: https://sg.run/r6EEA
semgrep.dev:
rule:
r_id: 146569
rv_id: 1263222
rule_id: 2ZUz884
version_id: zyTb2X0
url: https://semgrep.dev/playground/r/zyTb2X0/javascript.node-crypto.security.aead-no-final.aead-no-final
origin: community
languages:
- javascript
- typescript
severity: ERROR
patterns:
- pattern: |
$DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...)
...
$DECIPHER.update(...)
- pattern-not-inside: |
$DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...)
...
$DECIPHER.final(...)
- metavariable-regex:
metavariable: $ALGO
regex: .*(-gcm|-ccm|-ocb|chacha20-poly1305)$
- id: javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length
message: The call to 'createDecipheriv' with the Galois Counter Mode (GCM) mode
of operation is missing an expected authentication tag length. If the expected
authentication tag length is not specified or otherwise checked, the application
might be tricked into verifying a shorter-than-expected authentication tag. This
can be abused by an attacker to spoof ciphertexts or recover the implicit authentication
key of GCM, allowing arbitrary forgeries.
metadata:
cwe:
- 'CWE-310: CWE CATEGORY: Cryptographic Issues'
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
category: security
subcategory:
- vuln
technology:
- node-crypto
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
references:
- https://www.securesystems.de/blog/forging_ciphertexts_under_Galois_Counter_Mode_for_the_Node_js_crypto_module/
- https://nodejs.org/api/crypto.html#cryptocreatedecipherivalgorithm-key-iv-options
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures/
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length
shortlink: https://sg.run/NbGG1
semgrep.dev:
rule:
r_id: 146571
rv_id: 1263223
rule_id: j2UgPP3
version_id: pZT03qd
url: https://semgrep.dev/playground/r/pZT03qd/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length
origin: community
languages:
- javascript
- typescript
severity: ERROR
patterns:
- pattern: |
$CRYPTO.createDecipheriv('$ALGO', $KEY, $IV)
- metavariable-regex:
metavariable: $ALGO
regex: .*(-gcm)$
- id: php.lang.security.injection.tainted-exec.tainted-exec
languages:
- php
severity: WARNING
message: User input is passed to a function that executes a shell command. This
can lead to remote code execution.
metadata:
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
category: security
technology:
- php
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/Top10/A03_2021-Injection
subcategory:
- vuln
impact: HIGH
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/php.lang.security.injection.tainted-exec.tainted-exec
shortlink: https://sg.run/kxEEz
semgrep.dev:
rule:
r_id: 146572
rv_id: 1263286
rule_id: 10UOGG5
version_id: ExTExyR
url: https://semgrep.dev/playground/r/ExTExyR/php.lang.security.injection.tainted-exec.tainted-exec
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: $_GET
- pattern: $_POST
- pattern: $_COOKIE
- pattern: $_REQUEST
- pattern: file_get_contents('php://input')
pattern-sanitizers:
- patterns:
- pattern-either:
- pattern: escapeshellcmd(...)
- pattern: escapeshellarg(...)
pattern-sinks:
- patterns:
- pattern-either:
- pattern: exec(...)
- pattern: system(...)
- pattern: passthru(...)
- patterns:
- pattern: proc_open(...)
- pattern-not: proc_open([...], ...)
- pattern: popen(...)
- pattern: expect_popen(...)
- pattern: shell_exec(...)
- pattern: |
`...`
- id: yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false
languages:
- yaml
message: 'Found ''x-openai-isConsequential: false'' in a state-changing HTTP method:
$METHOD $PATH. This Action configuration will enable the ''Always Allow'' option
for state-changing HTTP methods, such as POST, PUT, PATCH, or DELETE. The risk
of a user selecting the ''Always Allow'' button is that the agent could perform
unintended actions on behalf of the user. When working with sensitive functionality,
it is always best to include a Human In The Loop (HITL) type of control. Consider
the trade-off between security and user friction and then make a risk-based decision
about this function.'
severity: WARNING
pattern-either:
- pattern-inside: |
post:
...
x-openai-isConsequential: false
- pattern-inside: |
put:
...
x-openai-isConsequential: false
- pattern-inside: |
patch:
...
x-openai-isConsequential: false
- pattern-inside: |
delete:
...
x-openai-isConsequential: false
metadata:
category: security
subcategory:
- audit
technology:
- openapi
- openai
likelihood: HIGH
impact: HIGH
confidence: HIGH
cwe: 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')'
owasp:
- A04:2021 Insecure Design
- LLM08:2023 - Excessive Agency
references:
- https://platform.openai.com/docs/actions/consequential-flag
- https://owasp.org/Top10/A04_2021-Insecure_Design/
- https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false
shortlink: https://sg.run/x8EEP
semgrep.dev:
rule:
r_id: 146574
rv_id: 947071
rule_id: yyURooD
version_id: WrTEZN8
url: https://semgrep.dev/playground/r/WrTEZN8/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false
origin: community
- id: python.lang.security.insecure-uuid-version.insecure-uuid-version
patterns:
- pattern: uuid.uuid1(...)
message: Using UUID version 1 for UUID generation can lead to predictable UUIDs
based on system information (e.g., MAC address, timestamp). This may lead to security
risks such as the sandwich attack. Consider using `uuid.uuid4()` instead for better
randomness and security.
metadata:
references:
- https://www.landh.tech/blog/20230811-sandwich-attack/
cwe:
- 'CWE-330: Use of Insufficiently Random Values'
owasp:
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.3.2 Insecure UUID Generation
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v63-random-values
version: '4'
category: security
technology:
- python
subcategory:
- audit
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.lang.security.insecure-uuid-version.insecure-uuid-version
shortlink: https://sg.run/BYBgW
semgrep.dev:
rule:
r_id: 148295
rv_id: 1263539
rule_id: kxUd1yD
version_id: O9Tpx97
url: https://semgrep.dev/playground/r/O9Tpx97/python.lang.security.insecure-uuid-version.insecure-uuid-version
origin: community
languages:
- python
severity: WARNING
fix-regex:
regex: uuid1
replacement: uuid4
- id: go.lang.security.audit.crypto.sha224-hash.sha224-hash
pattern-either:
- patterns:
- pattern-inside: |
import "crypto/sha256"
...
- pattern-either:
- pattern: |
sha256.New224()
- pattern: |
sha256.Sum224(...)
- patterns:
- pattern-inside: |
import "golang.org/x/crypto/sha3"
...
- pattern-either:
- pattern: |
sha3.New224()
- pattern: |
sha3.Sum224(...)
message: This code uses a 224-bit hash function, which is deprecated or disallowed
in some security policies. Consider updating to a stronger hash function such
as SHA-384 or higher to ensure compliance and security.
languages:
- go
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-328: Use of Weak Hash'
category: security
technology:
- go
references:
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/go.lang.security.audit.crypto.sha224-hash.sha224-hash
shortlink: https://sg.run/ReJwY
semgrep.dev:
rule:
r_id: 151749
rv_id: 1262925
rule_id: GdUvElR
version_id: 9lT4b4w
url: https://semgrep.dev/playground/r/9lT4b4w/go.lang.security.audit.crypto.sha224-hash.sha224-hash
origin: community
- id: java.lang.security.audit.crypto.use-of-sha224.use-of-sha224
message: This code uses a 224-bit hash function, which is deprecated or disallowed
in some security policies. Consider updating to a stronger hash function such
as SHA-384 or higher to ensure compliance and security.
languages:
- java
severity: WARNING
metadata:
functional-categories:
- crypto::search::hash-algorithm::javax.crypto
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-328: Use of Weak Hash'
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
category: security
technology:
- java
references:
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224
shortlink: https://sg.run/Ab2KQ
semgrep.dev:
rule:
r_id: 151750
rv_id: 1263017
rule_id: ReUDGEz
version_id: YDTZewo
url: https://semgrep.dev/playground/r/YDTZewo/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224
origin: community
pattern-either:
- pattern: org.apache.commons.codec.digest.DigestUtils.getSha3_224Digest()
- pattern: org.apache.commons.codec.digest.DigestUtils.getSha512_224Digest()
- pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224(...)
- pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224Hex(...)
- pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224(...)
- pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224Hex(...)
- pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_224)
- pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_512_224)
- pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA3_224)
- patterns:
- pattern: java.security.MessageDigest.getInstance("$ALGO", ...);
- metavariable-regex:
metavariable: $ALGO
regex: .*224
- id: php.lang.security.audit.sha224-hash.sha224-hash
pattern-either:
- pattern: hash('sha224', ...);
- pattern: hash('sha512/224', ...);
- pattern: hash('sha3-224', ...);
- pattern: hash_hmac('sha224', ...);
- pattern: hash_hmac('sha512/224', ...);
- pattern: hash_hmac('sha3-224', ...);
message: This code uses a 224-bit hash function, which is deprecated or disallowed
in some security policies. Consider updating to a stronger hash function such
as SHA-384 or higher to ensure compliance and security.
metadata:
cwe:
- 'CWE-328: Use of Weak Hash'
references:
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
category: security
technology:
- php
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- audit
likelihood: LOW
impact: LOW
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/php.lang.security.audit.sha224-hash.sha224-hash
shortlink: https://sg.run/BYXqv
semgrep.dev:
rule:
r_id: 151751
rv_id: 1263275
rule_id: AbU97EA
version_id: bZT53Jo
url: https://semgrep.dev/playground/r/bZT53Jo/php.lang.security.audit.sha224-hash.sha224-hash
origin: community
languages:
- php
severity: WARNING
- id: python.lang.security.audit.sha224-hash.sha224-hash
message: This code uses a 224-bit hash function, which is deprecated or disallowed
in some security policies. Consider updating to a stronger hash function such
as SHA-384 or higher to ensure compliance and security.
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
category: security
technology:
- python
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/python.lang.security.audit.sha224-hash.sha224-hash
shortlink: https://sg.run/Db1Yv
semgrep.dev:
rule:
r_id: 151752
rv_id: 1263511
rule_id: BYUX0y9
version_id: 5PTo1QL
url: https://semgrep.dev/playground/r/5PTo1QL/python.lang.security.audit.sha224-hash.sha224-hash
origin: community
severity: WARNING
languages:
- python
pattern-either:
- pattern: hashlib.sha224(...)
- pattern: hashlib.sha3_224(...)
- id: ruby.lang.security.audit.sha224-hash.sha224-hash
message: This code uses a 224-bit hash function, which is deprecated or disallowed
in some security policies. Consider updating to a stronger hash function such
as SHA-384 or higher to ensure compliance and security.
metadata:
cwe:
- 'CWE-328: Use of Weak Hash'
references:
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography
category: security
technology:
- ruby
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: LOW
impact: LOW
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Insecure Hashing Algorithm
source: https://semgrep.dev/r/ruby.lang.security.audit.sha224-hash.sha224-hash
shortlink: https://sg.run/WABbo
semgrep.dev:
rule:
r_id: 151753
rv_id: 1263592
rule_id: DbU60wQ
version_id: 8KT5rRY
url: https://semgrep.dev/playground/r/8KT5rRY/ruby.lang.security.audit.sha224-hash.sha224-hash
origin: community
languages:
- ruby
severity: WARNING
pattern-either:
- pattern: Digest::SHA224.$FUNC
- pattern: OpenSSL::Digest::SHA224.$FUNC
- pattern: SHA3::Digest::SHA224(...)
- patterns:
- pattern-either:
- pattern: OpenSSL::HMAC.hexdigest("$ALGO", ...)
- pattern: OpenSSL::HMAC.digest("$ALGO", ...)
- pattern: OpenSSL::HMAC.new($KEY, "$ALGO")
- pattern: OpenSSL::Digest.digest("$ALGO", ...)
- pattern: OpenSSL::Digest.new("$ALGO", ...)
- metavariable-regex:
metavariable: $ALGO
regex: .*224
- id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql
patterns:
- pattern-inside: |
resource "google_sql_database_instance" "..." {
...
database_version = "$DB"
...
}
- pattern-inside: |
resource "google_sql_database_instance" "..." {
...
ip_configuration {
...
ssl_mode = $VALUE
...
}
...
}
- pattern-not-inside: |
resource "google_sql_database_instance" "..." {
...
ip_configuration {
...
ssl_mode = "TRUSTED_CLIENT_CERTIFICATE_REQUIRED"
...
}
...
}
- metavariable-regex:
metavariable: $DB
regex: .*(MYSQL|POSTGRES).*
- focus-metavariable: $VALUE
fix: |
"TRUSTED_CLIENT_CERTIFICATE_REQUIRED"
message: Ensure all Cloud SQL database instance require incoming connections to
use SSL. To enable this for PostgresSQL and MySQL, use `ssl_mode="TRUSTED_CLIENT_CERTIFICATE_REQUIRED"`.
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
category: security
technology:
- terraform
- gcp
references:
- https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql
shortlink: https://sg.run/WANR2
semgrep.dev:
rule:
r_id: 153509
rv_id: 1263874
rule_id: 5rUdGAz
version_id: 2KTv22E
url: https://semgrep.dev/playground/r/2KTv22E/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql
origin: community
languages:
- hcl
severity: WARNING
- id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver
patterns:
- pattern-inside: |
resource "google_sql_database_instance" "..." {
...
database_version = "$DB"
...
}
- pattern-inside: |
resource "google_sql_database_instance" "..." {
...
ip_configuration {
...
ssl_mode = $VALUE
...
}
...
}
- pattern-not-inside: |
resource "google_sql_database_instance" "..." {
...
ip_configuration {
...
ssl_mode = "ENCRYPTED_ONLY"
...
}
...
}
- metavariable-regex:
metavariable: $DB
regex: .*(SQLSERVER).*
- focus-metavariable: $VALUE
fix: |
"ENCRYPTED_ONLY"
message: Ensure all Cloud SQL database instance require incoming connections to
use SSL. For SQL Server, `ssl_mode="ENCRYPTED_ONLY"` is the most secure value
that is supported.
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
category: security
technology:
- terraform
- gcp
references:
- https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver
shortlink: https://sg.run/0o92j
semgrep.dev:
rule:
r_id: 153510
rv_id: 1263875
rule_id: GdUvX6A
version_id: X0Tzyyl
url: https://semgrep.dev/playground/r/X0Tzyyl/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver
origin: community
languages:
- hcl
severity: WARNING
- id: python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true
message: Function `flask.url_for` with `_external=True` argument will generate URLs
using the `Host` header of the HTTP request, which may lead to security risks
such as Host header injection
metadata:
cwe:
- 'CWE-673: External Influence of Sphere Definition'
owasp:
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- flask
references:
- https://flask.palletsprojects.com/en/latest/api/#flask.url_for
- https://portswigger.net/kb/issues/00500300_host-header-injection
subcategory:
- audit
likelihood: MEDIUM
impact: LOW
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Other
source: https://semgrep.dev/r/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true
shortlink: https://sg.run/gEGeR
semgrep.dev:
rule:
r_id: 191541
rv_id: 1263418
rule_id: JDU5oql
version_id: K3TKk6n
url: https://semgrep.dev/playground/r/K3TKk6n/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true
origin: community
languages:
- python
severity: WARNING
patterns:
- pattern-not: flask.url_for(..., _external=False, ...)
- pattern-not: url_for(..., _external=False, ...)
- pattern-either:
- pattern: flask.url_for(..., _external=$VAR, ...)
- pattern: url_for(..., _external=$VAR, ...)
- id: php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit
languages:
- php
severity: WARNING
message: Detected usage of vulnerable functions with user input, which could lead
to SSRF vulnerabilities.
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: $_GET[...]
- pattern: $_POST[...]
- pattern: $_REQUEST[...]
- pattern: get_option(...)
- pattern: get_user_meta(...)
- pattern: get_query_var(...)
pattern-sinks:
- patterns:
- focus-metavariable: $URL
- pattern-either:
- pattern: wp_remote_get($URL, ...)
- pattern: wp_safe_remote_get($URL, ...)
- pattern: wp_safe_remote_request($URL, ...)
- pattern: wp_safe_remote_head($URL, ...)
- pattern: wp_oembed_get($URL, ...)
- pattern: vip_safe_wp_remote_get($URL, ...)
- pattern: wp_safe_remote_post($URL, ...)
paths:
include:
- '**/wp-content/plugins/**/*.php'
metadata:
cwe: 'CWE-918: Server-Side Request Forgery (SSRF)'
owasp: A10:2021 - Server-Side Request Forgery (SSRF)
category: security
confidence: MEDIUM
likelihood: MEDIUM
impact: HIGH
subcategory:
- audit
technology:
- Wordpress Plugins
references:
- https://developer.wordpress.org/reference/functions/wp_safe_remote_get/
- https://developer.wordpress.org/reference/functions/wp_remote_get/
- https://patchstack.com/articles/exploring-the-unpatched-wordpress-ssrf/
vulnerability_class:
- Server-Side Request Forgery (SSRF)
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit
shortlink: https://sg.run/K3y06
semgrep.dev:
rule:
r_id: 191611
rv_id: 1039233
rule_id: 6JUZyKX
version_id: JdTp6rq
url: https://semgrep.dev/playground/r/JdTp6rq/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit
origin: community
- id: yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor
languages:
- yaml
message: The Shai-hulud backdoor creates a purposefully vulnerable github action
with the name `discussion.yaml`.
paths:
include:
- '**/.github/workflows/discussion.yaml'
metadata:
category: security
cwe:
- 'CWE-509: Replicating Malicious Code (Virus or Worm)'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
technology:
- github-actions
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source_rule_url: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack
references:
- https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
source: https://semgrep.dev/r/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor
shortlink: https://sg.run/JdYPZ
semgrep.dev:
rule:
r_id: 238946
rv_id: 1263927
rule_id: 7KUDRPj
version_id: 6xT29ol
url: https://semgrep.dev/playground/r/6xT29ol/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor
origin: community
patterns:
- pattern-inside: 'steps: [...]'
- pattern-inside: |
- run: ...
...
- pattern: 'run: $SHELL'
- metavariable-pattern:
language: generic
metavariable: $SHELL
patterns:
- pattern-either:
- pattern: ${{ github.event.issue.title }}
- pattern: ${{ github.event.issue.body }}
- pattern: ${{ github.event.pull_request.title }}
- pattern: ${{ github.event.pull_request.body }}
- pattern: ${{ github.event.comment.body }}
- pattern: ${{ github.event.review.body }}
- pattern: ${{ github.event.review_comment.body }}
- pattern: ${{ github.event.pages. ... .page_name}}
- pattern: ${{ github.event.head_commit.message }}
- pattern: ${{ github.event.head_commit.author.email }}
- pattern: ${{ github.event.head_commit.author.name }}
- pattern: ${{ github.event.commits ... .author.email }}
- pattern: ${{ github.event.commits ... .author.name }}
- pattern: ${{ github.event.pull_request.head.ref }}
- pattern: ${{ github.event.pull_request.head.label }}
- pattern: ${{ github.event.pull_request.head.repo.default_branch }}
- pattern: ${{ github.head_ref }}
- pattern: ${{ github.event.inputs ... }}
- pattern: ${{ github.event.discussion.title }}
- pattern: ${{ github.event.discussion.body }}
- pattern: ${{ inputs ... }}
severity: ERROR
- id: go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface
languages:
- go
message: Deserializing into `interface{}` allows arbitrary data structures and types,
which can lead to security vulnerabilities (CWE-502). Use a concrete struct type
instead.
severity: WARNING
metadata:
cwe:
- 'CWE-502: Deserialization of Untrusted Data'
owasp:
- A08:2017 - Insecure Deserialization
- A08:2021 - Software and Data Integrity Failures
category: security
technology:
- go
confidence: HIGH
likelihood: MEDIUM
impact: HIGH
subcategory:
- vuln
references:
- https://cwe.mitre.org/data/definitions/502.html
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- 'Insecure Deserialization '
source: https://semgrep.dev/r/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface
shortlink: https://sg.run/6WbKL
semgrep.dev:
rule:
r_id: 274359
rv_id: 1409387
rule_id: 4bUAQDG
version_id: ZRTDkjk
url: https://semgrep.dev/playground/r/ZRTDkjk/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface
origin: community
patterns:
- pattern-either:
- pattern: |
var $VAR interface{}
...
json.Unmarshal($DATA, &$VAR)
- pattern: |
var $VAR interface{}
...
yaml.Unmarshal($DATA, &$VAR)
- pattern: |
var $VAR interface{}
...
xml.Unmarshal($DATA, &$VAR)
- id: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
message: "GitHub Actions step uses a mutable tag or branch reference. Tags and branch
names can be silently repointed by the action owner, enabling supply-chain attacks
\u2014 as seen in the trivy-action and kics-github-action compromises. Pin the
reference to a full 40-character commit SHA instead, e.g. `uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`."
severity: WARNING
languages:
- yaml
metadata:
category: security
cwe:
- 'CWE-1357: Reliance on Insufficiently Trustworthy Component'
- 'CWE-353: Missing Support for Integrity Check'
owasp:
- A08:2021 - Software and Data Integrity Failures
- A08:2025 - Software and Data Integrity Failures
references:
- https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions
technology:
- github-actions
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
- Other
source: https://semgrep.dev/r/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
shortlink: https://sg.run/2LgAL
semgrep.dev:
rule:
r_id: 288863
rv_id: 1413422
rule_id: GdUxYDx
version_id: xyTRDAd
url: https://semgrep.dev/playground/r/xyTRDAd/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
origin: community
patterns:
- pattern-inside: '{steps: ...}'
- pattern: |
uses: "$ACTION"
- metavariable-pattern:
metavariable: $ACTION
language: generic
patterns:
- pattern-not-regex: ^\./
- pattern-not-regex: ^docker://
- pattern-not-regex: '@[0-9a-f]{40}(\s|$)'
- id: yaml.github-actions.security.secrets-inherit.secrets-inherit
languages:
- yaml
severity: ERROR
message: 'This workflow uses `secrets: inherit` to pass all of the calling workflow''s
secrets to a reusable workflow. This violates the principle of least privilege
because the called workflow receives access to every secret in the repository,
not just the ones it needs. If the called workflow is compromised or sourced from
a third party, an attacker gains access to all repository secrets. Instead, explicitly
pass only the secrets that the called workflow requires using the `secrets:` map,
e.g. `secrets: { MY_SECRET: ${{ secrets.MY_SECRET }} }`.'
metadata:
category: security
cwe:
- 'CWE-250: Execution with Unnecessary Privileges'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://docs.github.com/en/actions/sharing-automations/reusing-workflows#passing-inputs-and-secrets-to-a-reusable-workflow
- https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions
technology:
- github-actions
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/yaml.github-actions.security.secrets-inherit.secrets-inherit
shortlink: https://sg.run/X2PZB
semgrep.dev:
rule:
r_id: 288864
rv_id: 1413424
rule_id: ReUQnKg
version_id: e1T42L1
url: https://semgrep.dev/playground/r/e1T42L1/yaml.github-actions.security.secrets-inherit.secrets-inherit
origin: community
patterns:
- pattern-inside: |
jobs:
...
- pattern: 'secrets: inherit'
- id: package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age
pattern-either:
- patterns:
- pattern-regex: (?ms)\[install\](?P<TARGET>[^\[]*?)(?=\[|\z)
- metavariable-regex:
metavariable: $TARGET
regex: ^(?![\s\S]*minimumReleaseAge)
- focus-metavariable: $TARGET
- patterns:
- pattern-regex: minimumReleaseAge\s*=\s*\d+
- pattern-regex: =\s*(?P<AGE>\d+)
- metavariable-comparison:
metavariable: $AGE
comparison: int($AGE) < 604800
- focus-metavariable: $AGE
- patterns:
- pattern-regex: (?m)minimumReleaseAge[ \t]*=[ \t]*(?P<VAL>[^\s\d][^\n]*)
- focus-metavariable: $VAL
- patterns:
- pattern-regex: (?m)minimumReleaseAge\s*=\s*$
message: 'This bunfig.toml does not set a minimum release age or sets it too low.
Newly published packages can be malicious or unstable. Add `minimumReleaseAge
= 604800` under the `[install]` section to wait 7 days before resolving newly
published package versions. Added in: v1.3 Reference: https://bun.sh/docs/runtime/bunfig'
languages:
- generic
severity: MEDIUM
paths:
include:
- '**/bunfig.toml'
- '**/.bunfig.toml'
metadata:
category: security
technology:
- bun
- javascript
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
owasp:
- A08:2021 - Software and Data Integrity Failures
confidence: HIGH
likelihood: LOW
impact: HIGH
subcategory:
- audit
vulnerability_class:
- Insecure Configuration
references:
- https://bun.sh/docs/runtime/bunfig
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age
shortlink: https://sg.run/JqPrR
semgrep.dev:
rule:
r_id: 291646
rv_id: 1423385
rule_id: oqUyJOb
version_id: BjTyRe5
url: https://semgrep.dev/playground/r/BjTyRe5/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age
origin: community
- id: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown
pattern-either:
- patterns:
- pattern-inside: |
updates:
...
- pattern: |
- package-ecosystem: $ECOSYSTEM
...
- pattern-not: |
- package-ecosystem: $ECOSYSTEM
...
cooldown:
...
...
- patterns:
- pattern-inside: |
updates:
...
- pattern-regex: default-days\s*:\s*(?P<DAYS>\d+)
- metavariable-comparison:
metavariable: $DAYS
comparison: int($DAYS) < 7
- focus-metavariable: $DAYS
- patterns:
- pattern-inside: |
updates:
...
- pattern: |
cooldown:
default-days: $DAYS
- metavariable-regex:
metavariable: $DAYS
regex: ^\D
- focus-metavariable: $DAYS
message: 'This Dependabot configuration does not set a cooldown period. Newly published
packages can be malicious or unstable. Add a `cooldown` block with `default-days:
7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing
updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown'
languages:
- yaml
severity: MEDIUM
paths:
include:
- '**/.github/dependabot.yml'
- '**/.github/dependabot.yaml'
metadata:
category: security
technology:
- dependabot
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
owasp:
- A08:2021 - Software and Data Integrity Failures
confidence: HIGH
likelihood: LOW
impact: HIGH
subcategory:
- audit
vulnerability_class:
- Insecure Configuration
references:
- https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown
shortlink: https://sg.run/5WvGK
semgrep.dev:
rule:
r_id: 291647
rv_id: 1423386
rule_id: zdUArOL
version_id: DkTwEGl
url: https://semgrep.dev/playground/r/DkTwEGl/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown
origin: community
- id: package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age
pattern-either:
- patterns:
- pattern-regex: (?:(?:^---\n)(?:[^\n]*\n)|^)(?P<TARGET>(?:(?!\n---)[\s\S])*\S(?:(?!\n---)[\s\S])*)
- pattern-not-regex: min-release-age
- focus-metavariable: $TARGET
- patterns:
- pattern-regex: min-release-age\s*=\s*\d+
- pattern-regex: =\s*(?P<AGE>\d+)
- metavariable-comparison:
metavariable: $AGE
comparison: int($AGE) < 7
- focus-metavariable: $AGE
- patterns:
- pattern-regex: (?m)min-release-age[ \t]*=[ \t]*(?P<VAL>[^\s\d][^\n]*)
- focus-metavariable: $VAL
- patterns:
- pattern-regex: (?m)min-release-age\s*=\s*$
message: 'This .npmrc does not set a minimum release age or sets it too low. Newly
published packages can be malicious or unstable. Add `min-release-age = 7` to
wait 7 days before resolving newly published package versions. Added in: v11.10
Reference: https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/'
languages:
- generic
severity: MEDIUM
paths:
include:
- '**/.npmrc'
metadata:
category: security
technology:
- npm
- javascript
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
owasp:
- A08:2021 - Software and Data Integrity Failures
confidence: HIGH
likelihood: LOW
impact: HIGH
subcategory:
- audit
vulnerability_class:
- Insecure Configuration
references:
- https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/
- https://github.com/npm/cli/pull/8965
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age
shortlink: https://sg.run/GRo1z
semgrep.dev:
rule:
r_id: 291648
rv_id: 1423387
rule_id: pKU6A82
version_id: WrT7LdL
url: https://semgrep.dev/playground/r/WrT7LdL/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age
origin: community
- id: package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies
message: 'Missing or incorrect blockExoticSubdeps. Set `blockExoticSubdeps: true`
to transitive dependencies from being installed from untrusted sources. Added
in: v10.26.0 Reference: https://pnpm.io/settings#blockexoticsubdeps'
languages:
- yaml
severity: MEDIUM
paths:
include:
- '**/pnpm-workspace.yaml'
pattern-either:
- patterns:
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:packages|catalog)\s*:)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
- focus-metavariable: $TARGET
- patterns:
- pattern: |
blockExoticSubdeps: $VAL
- metavariable-regex:
metavariable: $VAL
regex: ^(?!true$).+
- focus-metavariable: $VAL
- patterns:
- pattern-regex: (?m)^\s*blockExoticSubdeps\s*:\s*$
metadata:
category: security
technology:
- pnpm
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
owasp:
- A08:2021 - Software and Data Integrity Failures
confidence: HIGH
likelihood: LOW
impact: HIGH
subcategory:
- audit
vulnerability_class:
- Insecure Configuration
references:
- https://pnpm.io/settings#blockexoticsubdeps
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies
shortlink: https://sg.run/RrWRv
semgrep.dev:
rule:
r_id: 291649
rv_id: 1423388
rule_id: 2ZUQEZ5
version_id: 0bTGnwj
url: https://semgrep.dev/playground/r/0bTGnwj/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies
origin: community
- id: package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age
message: 'This pnpm workspace configuration does not set a minimum release age.
Newly published packages can be malicious or unstable. Add `minimumReleaseAge:
10080` (minutes) to wait at least seven days before installing newly published
package versions. Added in: v10.16.0 Reference: https://pnpm.io/settings#minimumreleaseage'
languages:
- yaml
severity: MEDIUM
paths:
include:
- '**/pnpm-workspace.yaml'
pattern-either:
- patterns:
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:packages|catalog)\s*:)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
- focus-metavariable: $TARGET
- patterns:
- pattern-regex: ^\s*minimumReleaseAge\s*:\s*(?P<AGE>\d+)
- metavariable-comparison:
metavariable: $AGE
comparison: int($AGE) < 10080
- focus-metavariable: $AGE
- patterns:
- pattern: |
minimumReleaseAge: $AGE
- metavariable-regex:
metavariable: $AGE
regex: ^\D
- focus-metavariable: $AGE
- patterns:
- pattern-regex: (?m)^\s*minimumReleaseAge\s*:\s*$
metadata:
category: security
technology:
- pnpm
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
owasp:
- A08:2021 - Software and Data Integrity Failures
confidence: HIGH
likelihood: LOW
impact: HIGH
subcategory:
- audit
vulnerability_class:
- Insecure Configuration
references:
- https://pnpm.io/settings#minimumreleaseage
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age
shortlink: https://sg.run/Aj0o0
semgrep.dev:
rule:
r_id: 291650
rv_id: 1423389
rule_id: X5Uwn1n
version_id: K3TgxrW
url: https://semgrep.dev/playground/r/K3TgxrW/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age
origin: community
- id: package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy
message: 'Missing or incorrect trustPolicy. Set `trustPolicy: no-downgrade` to prevent
malicious package updates from downgrading security settings. Added in: v10.21.0
Reference: https://pnpm.io/settings#trustpolicy'
languages:
- yaml
severity: MEDIUM
paths:
include:
- '**/pnpm-workspace.yaml'
pattern-either:
- patterns:
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:packages|catalog)\s*:)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
- focus-metavariable: $TARGET
- patterns:
- pattern: |
trustPolicy: $VAL
- metavariable-regex:
metavariable: $VAL
regex: ^(?!no-downgrade$).+
- focus-metavariable: $VAL
- patterns:
- pattern-regex: (?m)^\s*trustPolicy\s*:\s*$
metadata:
category: security
technology:
- pnpm
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
owasp:
- A08:2021 - Software and Data Integrity Failures
confidence: HIGH
likelihood: LOW
impact: HIGH
subcategory:
- audit
vulnerability_class:
- Insecure Configuration
references:
- https://pnpm.io/settings#minimumreleaseage
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy
shortlink: https://sg.run/B2Kz7
semgrep.dev:
rule:
r_id: 291651
rv_id: 1423390
rule_id: j2U6J8N
version_id: qkTvDQn
url: https://semgrep.dev/playground/r/qkTvDQn/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy
origin: community
- id: package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age
pattern-either:
- patterns:
- pattern-inside: |
"packageRules": [
...
]
- pattern-either:
- pattern: |
{ ..., "matchPackageNames": [...], ... }
- pattern: |
{ ..., "matchPackagePatterns": [...], ... }
- pattern: |
{ ..., "matchDepTypes": [...], ... }
- pattern-not: |
{
...,
"minimumReleaseAge": $AGE,
...
}
- pattern-not: |
{
...,
"minimumReleaseAge": false,
...
}
- patterns:
- pattern-inside: |
"packageRules": [
...
]
- pattern-regex: '"minimumReleaseAge":\s*"(?P<AGE>\d+) days?"'
- metavariable-comparison:
metavariable: $AGE
comparison: int($AGE) < 7
- focus-metavariable: $AGE
- patterns:
- pattern-inside: |
"packageRules": [
...
]
- pattern: |
"minimumReleaseAge": "$AGE"
- metavariable-regex:
metavariable: $AGE
regex: ^(?!\d+ days?$)
- focus-metavariable: $AGE
message: 'This Renovate configuration does not set a minimum release age. Newly
published packages can be malicious or unstable. Add `"minimumReleaseAge": "7
days"` within a `packageRules` entry to wait 7 days before proposing updates to
newly published package versions. Set `"minimumReleaseAge": false` to set an exception
for minimal release age for the package rule. Added in: v42'
languages:
- json
severity: MEDIUM
paths:
include:
- '**/renovate.json'
- '**/renovate.json5'
- '**/.renovaterc'
- '**/.renovaterc.json'
- '**/.renovaterc.json5'
metadata:
category: security
technology:
- renovate
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
owasp:
- A08:2021 - Software and Data Integrity Failures
confidence: HIGH
likelihood: LOW
impact: HIGH
subcategory:
- audit
vulnerability_class:
- Insecure Configuration
references:
- https://docs.renovatebot.com/configuration-options/#minimumreleaseage
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age
shortlink: https://sg.run/D8l2q
semgrep.dev:
rule:
r_id: 291652
rv_id: 1443454
rule_id: 10UbQrX
version_id: jQT1KAX
url: https://semgrep.dev/playground/r/jQT1KAX/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age
origin: community
- id: package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown
pattern-either:
- patterns:
- pattern-regex: (?ms)\[tool\.uv\](?P<TARGET>[^\[]*?)(?=\[|\z)
- metavariable-regex:
metavariable: $TARGET
regex: ^(?![\s\S]*exclude-newer)
- focus-metavariable: $TARGET
- patterns:
- pattern-regex: exclude-newer\s*=\s*"(?P<DAYS>\d+) days?"
- metavariable-comparison:
metavariable: $DAYS
comparison: int($DAYS) < 7
- focus-metavariable: $DAYS
- patterns:
- pattern-regex: exclude-newer\s*=\s*"(?P<VAL>[^"]+)"
- metavariable-regex:
metavariable: $VAL
regex: ^(?!\d+ days?$)(?!\d{4}-\d{2}-\d{2}$)(?!\d{4}-\d{2}-\d{2}T)
- focus-metavariable: $VAL
message: 'This pyproject.toml configures uv but does not set a dependency cooldown.
Newly published packages can be malicious or unstable. Add `exclude-newer = "7
days"` under `[tool.uv]` to wait 7 days before resolving newly published package
versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns'
languages:
- generic
severity: MEDIUM
paths:
include:
- '**/pyproject.toml'
- '**/uv.toml'
metadata:
category: security
technology:
- uv
- python
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
owasp:
- A08:2021 - Software and Data Integrity Failures
confidence: HIGH
likelihood: LOW
impact: HIGH
subcategory:
- audit
vulnerability_class:
- Insecure Configuration
references:
- https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown
shortlink: https://sg.run/WeY0Z
semgrep.dev:
rule:
r_id: 291653
rv_id: 1423392
rule_id: 9AUo6vE
version_id: YDTwLle
url: https://semgrep.dev/playground/r/YDTwLle/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown
origin: community
- id: package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate
pattern-either:
- patterns:
- pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?P<TARGET>^(?:nodeLinker|yarnPath|enableGlobalCache|npmScopes|npmRegistryServer)\s*:)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?=^---$|\z)
- focus-metavariable: $TARGET
- patterns:
- pattern-regex: (?m)npmMinimalAgeGate\s*:\s*['"]?(?P<DAYS>\d+)d['"]?
- metavariable-comparison:
metavariable: $DAYS
comparison: int($DAYS) < 7
- focus-metavariable: $DAYS
- patterns:
- pattern-regex: (?m)npmMinimalAgeGate[ \t]*:[ \t]*(?P<VAL>\S+)
- metavariable-regex:
metavariable: $VAL
regex: ^(?!['"]?\d+d['"]?$)
- focus-metavariable: $VAL
- patterns:
- pattern-regex: (?m)^npmMinimalAgeGate\s*:\s*$
message: 'This .yarnrc.yml does not set a minimal age gate or sets it too low. Newly
published packages can be malicious or unstable. Add `npmMinimalAgeGate: "7d"`
to wait 7 days before resolving newly published package versions. Added in: 4.10
Reference: https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate'
languages:
- yaml
severity: MEDIUM
paths:
include:
- '**/.yarnrc.yml'
metadata:
category: security
technology:
- yarn
- javascript
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
owasp:
- A08:2021 - Software and Data Integrity Failures
confidence: HIGH
likelihood: LOW
impact: HIGH
subcategory:
- audit
vulnerability_class:
- Insecure Configuration
references:
- https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate
shortlink: https://sg.run/0gvNq
semgrep.dev:
rule:
r_id: 291654
rv_id: 1423393
rule_id: yyUBeEz
version_id: JdTnXlj
url: https://semgrep.dev/playground/r/JdTnXlj/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate
origin: community
- id: package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age
message: "This poetry.toml does not set a dependency cooldown via `solver.min-release-age`.
Without a cooldown, Poetry may resolve newly published package versions that have
not yet been vetted by the community. Supply chain attacks frequently involve
publishing a malicious version of a popular package and waiting for it to be pulled
in \u2014 most are detected and removed within days. Set `min-release-age = 7`
under `[solver]` to require that package versions are at least 7 days old before
they are considered during dependency resolution. Added in: v2.4.0"
languages:
- generic
severity: MEDIUM
paths:
include:
- '**/poetry.toml'
- '**/config.toml'
pattern-either:
- pattern-regex: (?m)^\[solver\]\n(?:^(?!min-release-age|\[|---).*\n)*(?=^\[|^---|\z)
- pattern-regex: (?ms)^\[solver\](?:[^\[]*?)min-release-age\s*=\s*(?P<TARGET>"[^"]*"|[0-6](?:\s|#|$)|false)
metadata:
category: security
technology:
- poetry
- python
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
owasp:
- A08:2021 - Software and Data Integrity Failures
confidence: MEDIUM
likelihood: LOW
impact: MEDIUM
subcategory:
- audit
vulnerability_class:
- Insecure Configuration
references:
- https://python-poetry.org/docs/configuration/#solvermin-release-age
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age
shortlink: https://sg.run/JqnYZ
semgrep.dev:
rule:
r_id: 309390
rv_id: 1443453
rule_id: kxUjBPy
version_id: X0TYPX6
url: https://semgrep.dev/playground/r/X0TYPX6/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age
origin: community
- id: package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown
message: 'A Gemfile `source` declaration without a `cooldown` (or with a cooldown
below 7 days) allows Bundler to resolve newly published gem versions immediately,
before the community has had time to detect malicious releases. The May 2026 RubyGems
supply-chain attack demonstrated that threat actors can push compromised gem versions
and have them automatically pulled into builds within minutes. Add `cooldown:
7` to each public source declaration so Bundler ignores gem versions published
within the last 7 days during dependency resolution (e.g. `source "https://rubygems.org",
cooldown: 7`). If you operate an internal or private registry where the supply-chain
risk is lower, use `cooldown: 0` as an explicit bypass. Note: this feature requires
Bundler >= 4.0.13. Cooldown only applies during `bundle update` and `bundle add`;
`bundle install` with an existing lockfile is unaffected.'
languages:
- ruby
severity: MEDIUM
paths:
include:
- '**/Gemfile'
- '**/gems.rb'
exclude:
- '**/vendor/**'
- '**/.bundle/**'
pattern-either:
- patterns:
- pattern: source "...", ...
- pattern-not: 'source "...", ..., cooldown: $N, ...'
- patterns:
- pattern: 'source "...", ..., cooldown: $N, ...'
- metavariable-comparison:
metavariable: $N
comparison: $N > 0 and $N < 7
- focus-metavariable: $N
metadata:
category: security
technology:
- bundler
- ruby
cwe:
- 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere'
owasp:
- A08:2021 - Software and Data Integrity Failures
confidence: MEDIUM
likelihood: LOW
impact: MEDIUM
subcategory:
- audit
vulnerability_class:
- Insecure Configuration
references:
- https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
source: https://semgrep.dev/r/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown
shortlink: https://sg.run/5Wlkl
semgrep.dev:
rule:
r_id: 309391
rv_id: 1443455
rule_id: wdUzPbP
version_id: 1QTEjAN
url: https://semgrep.dev/playground/r/1QTEjAN/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown
origin: community
- id: yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell
languages:
- yaml
message: "A `run:` step pipes the output of `curl` or `wget` directly into a shell
interpreter. This is the \"curl | bash\" install pattern \u2014 if the remote
server is compromised or the URL is hijacked, an attacker can execute arbitrary
code in your CI runner. Consider downloading the file first, verifying its checksum
or signature, and then executing it."
metadata:
category: security
cwe:
- 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS
Command Injection'')'
owasp:
- A03:2021 - Injection
- A03:2025 - Injection
references:
- https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions
- https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/
technology:
- github-actions
- bash
- curl
cwe2021-top25: true
cwe2022-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Command Injection
source: https://semgrep.dev/r/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell
shortlink: https://sg.run/GR8K1
semgrep.dev:
rule:
r_id: 309392
rv_id: 1443456
rule_id: x8UAgrE
version_id: 9lT3zYb
url: https://semgrep.dev/playground/r/9lT3zYb/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell
origin: community
patterns:
- pattern-inside: 'steps: [...]'
- pattern-inside: |
- run: ...
...
- pattern: 'run: $SHELL'
- metavariable-pattern:
language: bash
metavariable: $SHELL
patterns:
- pattern-either:
- pattern: curl ... | $CMD ...
- pattern: wget ... | $CMD ...
- metavariable-regex:
metavariable: $CMD
regex: ^(bash|sh|python3?|ruby|perl)$
severity: ERROR
- id: yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret
languages:
- yaml
message: "A secret is exposed in the workflow-level `env:` block, making it available
to every job and step in this workflow \u2014 including any untrusted code run
in pull-request workflows. Scope secrets as narrowly as possible: prefer step-level
`env:` so the secret is only available where it is actually needed."
metadata:
category: security
cwe:
- 'CWE-732: Incorrect Permission Assignment for Critical Resource'
owasp:
- A01:2021 - Broken Access Control
- A01:2025 - Broken Access Control
references:
- https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-secrets
- https://docs.github.com/en/actions/learn-github-actions/variables#defining-environment-variables-for-a-single-workflow
technology:
- github-actions
subcategory:
- audit
likelihood: LOW
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authorization
source: https://semgrep.dev/r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret
shortlink: https://sg.run/Rrn12
semgrep.dev:
rule:
r_id: 309393
rv_id: 1443457
rule_id: OrUnq7z
version_id: yeTqX9r
url: https://semgrep.dev/playground/r/yeTqX9r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret
origin: community
patterns:
- pattern-inside: |
env:
...
- pattern-regex: \$\{\{\s*secrets\.
- pattern-not-inside: 'jobs: ...'
severity: WARNING
- id: ruby.rails.security.injection.tainted-sql-string.tainted-sql-string
languages:
- ruby
severity: ERROR
message: Detected user input used to manually construct a SQL string. This is usually
bad practice because manual construction could accidentally result in a SQL injection.
An attacker could use a SQL injection to steal or modify contents of the database.
Instead, use a parameterized query which is available by default in most database
engines. Alternatively, consider using an object-relational mapper (ORM) such
as ActiveRecord which will protect your queries.
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
category: security
technology:
- rails
references:
- https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: HIGH
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string
shortlink: https://sg.run/Y85o
semgrep.dev:
rule:
r_id: 14714
rv_id: 1263667
rule_id: bwU8gl
version_id: YDTZeLL
url: https://semgrep.dev/playground/r/YDTZeLL/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: params
- pattern: request
pattern-sanitizers:
- pattern: |
$PARAMS.slice(...)
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern-either:
- patterns:
- pattern: |
$RECORD.where($X,...)
- pattern: |
$RECORD.find(..., :conditions => $X,...)
- focus-metavariable: $X
- patterns:
- pattern: |
"$SQLVERB#{$EXPR}..."
- pattern-not-inside: |
$FUNC("...", "...#{$EXPR}...",...)
- focus-metavariable: $SQLVERB
- pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b
- patterns:
- pattern-either:
- pattern: Kernel::sprintf("$SQLSTR", $EXPR)
- pattern: |
"$SQLSTR" + $EXPR
- pattern: |
"$SQLSTR" % $EXPR
- pattern-not-inside: |
$FUNC("...", "...#{$EXPR}...",...)
- focus-metavariable: $EXPR
- metavariable-regex:
metavariable: $SQLSTR
regex: (?i)(select|delete|insert|create|update|alter|drop)\b
- id: php.lang.security.injection.tainted-sql-string.tainted-sql-string
languages:
- php
severity: ERROR
message: User data flows into this manually-constructed SQL string. User data can
be safely inserted into SQL strings using prepared statements or an object-relational
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
injection, which could let an attacker steal or manipulate data from the database.
Instead, use prepared statements (`$mysqli->prepare("INSERT INTO test(id, label)
VALUES (?, ?)");`) or a safe library.
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://owasp.org/www-community/attacks/SQL_Injection
category: security
technology:
- php
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/php.lang.security.injection.tainted-sql-string.tainted-sql-string
shortlink: https://sg.run/lZYG
semgrep.dev:
rule:
r_id: 14757
rv_id: 1263290
rule_id: qNUXdL
version_id: gETB7vY
url: https://semgrep.dev/playground/r/gETB7vY/php.lang.security.injection.tainted-sql-string.tainted-sql-string
origin: community
mode: taint
pattern-sanitizers:
- pattern-either:
- pattern: mysqli_real_escape_string(...)
- pattern: real_escape_string(...)
- pattern: $MYSQLI->real_escape_string(...)
pattern-sources:
- patterns:
- pattern-either:
- pattern: $_GET
- pattern: $_POST
- pattern: $_COOKIE
- pattern: $_REQUEST
pattern-sinks:
- pattern-either:
- patterns:
- pattern: |
sprintf($SQLSTR, ...)
- metavariable-regex:
metavariable: $SQLSTR
regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.*
- patterns:
- pattern: |
"...$EXPR..."
- metavariable-regex:
metavariable: $EXPR
regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.*
- patterns:
- pattern: |
"$SQLSTR".$EXPR
- metavariable-regex:
metavariable: $SQLSTR
regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.*
- id: php.lang.security.injection.tainted-url-host.tainted-url-host
languages:
- php
severity: WARNING
message: User data flows into the host portion of this manually-constructed URL.
This could allow an attacker to send data to their own server, potentially exposing
sensitive data such as cookies or authorization information sent with this request.
They could also probe internal servers or other resources that the server running
this code can access. (This is called server-side request forgery, or SSRF.) Do
not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or
hardcode the correct host.
metadata:
cwe:
- 'CWE-918: Server-Side Request Forgery (SSRF)'
owasp:
- A10:2021 - Server-Side Request Forgery (SSRF)
- A01:2025 - Broken Access Control
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
category: security
technology:
- php
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
impact: MEDIUM
likelihood: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Server-Side Request Forgery (SSRF)
source: https://semgrep.dev/r/php.lang.security.injection.tainted-url-host.tainted-url-host
shortlink: https://sg.run/Y8no
semgrep.dev:
rule:
r_id: 14758
rv_id: 1263291
rule_id: lBU8K1
version_id: QkTGqRd
url: https://semgrep.dev/playground/r/QkTGqRd/php.lang.security.injection.tainted-url-host.tainted-url-host
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: $_GET
- pattern: $_POST
- pattern: $_COOKIE
- pattern: $_REQUEST
pattern-sinks:
- pattern-either:
- patterns:
- pattern: |
sprintf($URLSTR, ...)
- metavariable-pattern:
metavariable: $URLSTR
language: generic
pattern: $SCHEME://%s
- patterns:
- pattern: |
"...{$EXPR}..."
- pattern-regex: |
.*://\{.*
- patterns:
- pattern: |
"...$EXPR..."
- pattern-regex: |
.*://\$.*
- patterns:
- pattern: |
"...".$EXPR
- pattern-regex: |
.*://["'].*
- id: php.lang.security.md5-used-as-password.md5-used-as-password
severity: WARNING
message: It looks like MD5 is used as a password hash. MD5 is not considered a secure
password hash because it can be cracked by an attacker in a short amount of time.
Use a suitable password hashing function such as bcrypt. You can use `password_hash($PASSWORD,
PASSWORD_BCRYPT, $OPTIONS);`.
languages:
- php
metadata:
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
references:
- https://tools.ietf.org/html/rfc6151
- https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision
- https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords
- https://github.com/returntocorp/semgrep-rules/issues/1609
- https://www.php.net/password_hash
category: security
technology:
- md5
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/php.lang.security.md5-used-as-password.md5-used-as-password
shortlink: https://sg.run/66YL
semgrep.dev:
rule:
r_id: 14759
rv_id: 1263294
rule_id: YGUD1O
version_id: PkTR37j
url: https://semgrep.dev/playground/r/PkTR37j/php.lang.security.md5-used-as-password.md5-used-as-password
origin: community
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern: md5(...)
- pattern: hash('md5', ...)
pattern-sinks:
- patterns:
- pattern: $FUNCTION(...)
- metavariable-regex:
metavariable: $FUNCTION
regex: (?i)(.*password.*)
- id: java.spring.security.injection.tainted-sql-string.tainted-sql-string
languages:
- java
severity: ERROR
message: User data flows into this manually-constructed SQL string. User data can
be safely inserted into SQL strings using prepared statements or an object-relational
mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL
injection, which could let an attacker steal or manipulate data from the database.
Instead, use prepared statements (`connection.PreparedStatement`) or a safe library.
metadata:
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
references:
- https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html
category: security
technology:
- spring
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: HIGH
impact: MEDIUM
confidence: MEDIUM
interfile: true
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/java.spring.security.injection.tainted-sql-string.tainted-sql-string
shortlink: https://sg.run/9rzz
semgrep.dev:
rule:
r_id: 14767
rv_id: 1409396
rule_id: 10UdRR
version_id: 44TbKvr
url: https://semgrep.dev/playground/r/44TbKvr/java.spring.security.injection.tainted-sql-string.tainted-sql-string
origin: community
options:
taint_assume_safe_numbers: true
taint_assume_safe_booleans: true
interfile: true
mode: taint
pattern-sources:
- patterns:
- pattern-either:
- pattern-inside: |
$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {
...
}
- pattern-inside: |
$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {
...
}
- metavariable-regex:
metavariable: $REQ
regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue)
- metavariable-regex:
metavariable: $TYPE
regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean))
- focus-metavariable: $SOURCE
pattern-sinks:
- patterns:
- pattern-either:
- pattern: |
"$SQLSTR" + ...
- pattern: |
"$SQLSTR".concat(...)
- patterns:
- pattern-inside: |
StringBuilder $SB = new StringBuilder("$SQLSTR");
...
- pattern: $SB.append(...)
- patterns:
- pattern-inside: |
$VAR = "$SQLSTR";
...
- pattern: $VAR += ...
- pattern: String.format("$SQLSTR", ...)
- patterns:
- pattern-inside: |
String $VAR = "$SQLSTR";
...
- pattern: String.format($VAR, ...)
- pattern-not-inside: System.out.println(...)
- pattern-not-inside: $LOG.info(...)
- pattern-not-inside: $LOG.warn(...)
- pattern-not-inside: $LOG.warning(...)
- pattern-not-inside: $LOG.debug(...)
- pattern-not-inside: $LOG.debugging(...)
- pattern-not-inside: $LOG.error(...)
- pattern-not-inside: new Exception(...)
- pattern-not-inside: throw ...;
- metavariable-regex:
metavariable: $SQLSTR
regex: (?i)(select|delete|insert|create|update|alter|drop)\b
- id: terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version
patterns:
- pattern-either:
- patterns:
- pattern: ssl_policy = $ANYTHING
- pattern-not-regex: ELBSecurityPolicy-TLS13-1-[23]-[(Res)0-9-]+
- pattern-not-regex: ELBSecurityPolicy-FS-1-2-[(Res)0-9-]+
- patterns:
- pattern: protocol = "HTTP"
- pattern-not-inside: |
resource $ANYTHING $NAME {
...
default_action {
...
redirect {
...
protocol = "HTTPS"
...
}
...
}
...
}
- pattern-inside: |
resource $RESOURCE $X {
...
}
- metavariable-pattern:
metavariable: $RESOURCE
patterns:
- pattern-either:
- pattern: |
"aws_lb_listener"
- pattern: |
"aws_alb_listener"
message: Detected an AWS load balancer with an insecure TLS version. TLS versions
less than 1.2 are considered insecure because they can be broken. To fix this,
set your `ssl_policy` to `"ELBSecurityPolicy-TLS13-1-2-Res-2021-06"`, or include
a default action to redirect to HTTPS.
metadata:
category: security
technology:
- terraform
- aws
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-326: Inadequate Encryption Strength'
references:
- https://www.ietf.org/rfc/rfc5246.txt
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version
shortlink: https://sg.run/187G
semgrep.dev:
rule:
r_id: 14966
rv_id: 1263747
rule_id: 2ZUP9K
version_id: ExTEx0y
url: https://semgrep.dev/playground/r/ExTEx0y/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version
origin: community
languages:
- hcl
severity: WARNING
- id: csharp.lang.security.sqli.csharp-sqli.csharp-sqli
mode: taint
pattern-sources:
- patterns:
- pattern: |
(string $X)
- pattern-not: |
"..."
pattern-propagators:
- pattern: (StringBuilder $B).$ANY(...,(string $X),...)
from: $X
to: $B
pattern-sinks:
- patterns:
- pattern-either:
- patterns:
- pattern: |
new $PATTERN($CMD,...)
- focus-metavariable: $CMD
- patterns:
- pattern: |
$CMD.$PATTERN = $VALUE;
- focus-metavariable: $VALUE
- metavariable-regex:
metavariable: $PATTERN
regex: ^(SqlCommand|CommandText|OleDbCommand|OdbcCommand|OracleCommand)$
pattern-sanitizers:
- pattern-either:
- pattern: |
$CMD.Parameters.Add(...)
- pattern: |
$CMD.Parameters.AddRange(...)
- pattern: |
$CMD.Parameters.AddWithValue(...)
- pattern: |
$CMD.Parameters[$IDX].Value = ...
by-side-effect: true
message: Detected a formatted string in a SQL statement. This could lead to SQL
injection if variables in the SQL statement are not properly sanitized. Use a
prepared statements instead. You can obtain a PreparedStatement using 'SqlCommand'
and 'SqlParameter'.
metadata:
category: security
technology:
- csharp
owasp:
- A01:2017 - Injection
- A03:2021 - Injection
- A05:2025 - Injection
cwe:
- 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command
(''SQL Injection'')'
confidence: MEDIUM
references:
- https://owasp.org/Top10/A03_2021-Injection
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- SQL Injection
source: https://semgrep.dev/r/csharp.lang.security.sqli.csharp-sqli.csharp-sqli
shortlink: https://sg.run/d2Xd
semgrep.dev:
rule:
r_id: 15078
rv_id: 1262648
rule_id: x8UxeP
version_id: RGT0LqW
url: https://semgrep.dev/playground/r/RGT0LqW/csharp.lang.security.sqli.csharp-sqli.csharp-sqli
origin: community
languages:
- csharp
severity: ERROR
- id: scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret
languages:
- scala
message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently
Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html
Consider using an appropriate security mechanism to protect the credentials (e.g.
keeping secrets in environment variables)'
metadata:
category: security
cwe:
- 'CWE-522: Insufficiently Protected Credentials'
owasp:
- A02:2017 - Broken Authentication
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/
technology:
- jwt
confidence: HIGH
references:
- https://owasp.org/Top10/A04_2021-Insecure_Design
cwe2021-top25: true
subcategory:
- audit
likelihood: MEDIUM
impact: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret
shortlink: https://sg.run/Z40o
semgrep.dev:
rule:
r_id: 15079
rv_id: 1263691
rule_id: OrU6W1
version_id: 7ZTE3kr
url: https://semgrep.dev/playground/r/7ZTE3kr/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret
origin: community
pattern-either:
- pattern: |
com.auth0.jwt.algorithms.Algorithm.HMAC256("...");
- pattern: |
$SECRET = "...";
...
com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET);
- pattern: |
class $CLASS {
...
$DECL $SECRET = "...";
...
def $FUNC (...): $RETURNTYPE = {
...
com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET);
...
}
...
}
- pattern: |
com.auth0.jwt.algorithms.Algorithm.HMAC384("...");
- pattern: |
$SECRET = "...";
...
com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET);
- pattern: |
class $CLASS {
...
$DECL $SECRET = "...";
...
def $FUNC (...): $RETURNTYPE = {
...
com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET);
...
}
...
}
- pattern: |
com.auth0.jwt.algorithms.Algorithm.HMAC512("...");
- pattern: |
$SECRET = "...";
...
com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET);
- pattern: |
class $CLASS {
...
$DECL $SECRET = "...";
...
def $FUNC (...): $RETURNTYPE = {
...
com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET);
...
}
...
}
severity: ERROR
- id: terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled
message: Enabling authentication ensures that all communications in the application
are authenticated. The `auth_settings` block needs to be filled out with the appropriate
auth backend settings
patterns:
- pattern: resource
- pattern-not-inside: |
resource "azurerm_app_service" "..." {
...
auth_settings {
...
enabled = true
...
}
...
}
- pattern-either:
- pattern-inside: |
resource "azurerm_app_service" "..." {
...
}
- pattern-inside: |
resource "azurerm_app_service" "..." {
...
auth_settings {
...
enabled = false
...
}
...
}
metadata:
cwe:
- 'CWE-287: Improper Authentication'
category: security
technology:
- terraform
- azure
references:
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#auth_settings
owasp:
- A02:2017 - Broken Authentication
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled
shortlink: https://sg.run/JxYw
semgrep.dev:
rule:
r_id: 15102
rv_id: 1263755
rule_id: 0oU23p
version_id: PkTR3P8
url: https://semgrep.dev/playground/r/PkTR3P8/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled
origin: community
languages:
- hcl
severity: ERROR
- id: terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2
message: Use the latest version of HTTP to ensure you are benefiting from security
fixes. Add `http2_enabled = true` to your appservice resource block
patterns:
- pattern: resource
- pattern-not-inside: |
resource "azurerm_app_service" "..." {
...
site_config {
...
http2_enabled = true
...
}
...
}
- pattern-either:
- pattern-inside: |
resource "azurerm_app_service" "..." {
...
}
- pattern-inside: |
resource "azurerm_app_service" "..." {
...
site_config {
...
http2_enabled = false
...
}
...
}
metadata:
cwe:
- 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response
Smuggling'')'
category: security
technology:
- terraform
- azure
references:
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#http2_enabled
owasp:
- A04:2021 - Insecure Design
- A06:2025 - Insecure Design
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Validation
source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2
shortlink: https://sg.run/5DkA
semgrep.dev:
rule:
r_id: 15103
rv_id: 1263756
rule_id: KxU7LJ
version_id: JdTzx98
url: https://semgrep.dev/playground/r/JdTzx98/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2
origin: community
languages:
- hcl
severity: INFO
- id: terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only
message: By default, clients can connect to App Service by using both HTTP or HTTPS.
HTTP should be disabled enabling the HTTPS Only setting.
patterns:
- pattern: resource
- pattern-not-inside: |
resource "azurerm_app_service" "..." {
...
https_only = true
...
}
- pattern-either:
- pattern-inside: |
resource "azurerm_app_service" "..." {
...
}
- pattern-inside: |
resource "azurerm_app_service" "..." {
...
https_only = false
...
}
metadata:
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
category: security
technology:
- terraform
- azure
references:
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#https_only
- https://docs.microsoft.com/en-us/azure/app-service/configure-ssl-bindings#enforce-https
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only
shortlink: https://sg.run/GOKp
semgrep.dev:
rule:
r_id: 15104
rv_id: 1263757
rule_id: qNUXwx
version_id: 5PTo1gg
url: https://semgrep.dev/playground/r/5PTo1gg/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only
origin: community
languages:
- hcl
severity: ERROR
- id: terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert
message: Detected an AppService that was not configured to use a client certificate.
Add `client_cert_enabled = true` in your resource block.
patterns:
- pattern: resource
- pattern-not-inside: |
resource "azurerm_app_service" "..." {
...
client_cert_enabled = true
...
}
- pattern-either:
- pattern-inside: |
resource "azurerm_app_service" "..." {
...
}
- pattern-inside: |
resource "azurerm_app_service" "..." {
...
client_cert_enabled = false
...
}
metadata:
cwe:
- 'CWE-295: Improper Certificate Validation'
category: security
technology:
- terraform
- azure
references:
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#client_cert_enabled
owasp:
- A03:2017 - Sensitive Data Exposure
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
subcategory:
- vuln
likelihood: MEDIUM
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert
shortlink: https://sg.run/RX1O
semgrep.dev:
rule:
r_id: 15105
rv_id: 1263758
rule_id: lBU8D6
version_id: GxTkedE
url: https://semgrep.dev/playground/r/GxTkedE/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert
origin: community
languages:
- hcl
severity: INFO
- id: terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy
message: Detected an AppService that was not configured to use TLS 1.2. Add `site_config.min_tls_version
= "1.2"` in your resource block.
patterns:
- pattern: min_tls_version = $ANYTHING
- pattern-inside: |
resource "azurerm_app_service" "$NAME" {
...
}
- pattern-not-inside: min_tls_version = "1.2"
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
category: security
technology:
- terraform
- azure
references:
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#min_tls_version
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy
shortlink: https://sg.run/AXRp
semgrep.dev:
rule:
r_id: 15106
rv_id: 1263759
rule_id: YGUDbZ
version_id: RGT0L4x
url: https://semgrep.dev/playground/r/RGT0L4x/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy
origin: community
languages:
- hcl
severity: ERROR
- id: terraform.azure.security.storage.storage-enforce-https.storage-enforce-https
message: Detected a Storage that was not configured to deny action by default. Add
`enable_https_traffic_only = true` in your resource block.
patterns:
- pattern-not-inside: |
resource "azurerm_storage_account" "..." {
...
enable_https_traffic_only = true
...
}
- pattern-inside: |
resource "azurerm_storage_account" "..." {
...
enable_https_traffic_only = false
...
}
metadata:
cwe:
- 'CWE-319: Cleartext Transmission of Sensitive Information'
category: security
technology:
- terraform
- azure
references:
- https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#enable_https_traffic_only
- https://docs.microsoft.com/en-us/azure/storage/common/storage-require-secure-transfer
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Mishandled Sensitive Information
source: https://semgrep.dev/r/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https
shortlink: https://sg.run/0y9v
semgrep.dev:
rule:
r_id: 15110
rv_id: 1263805
rule_id: pKUpDA
version_id: BjTkZ0A
url: https://semgrep.dev/playground/r/BjTkZ0A/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https
origin: community
languages:
- hcl
severity: WARNING
- id: kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind
metadata:
cwe:
- 'CWE-287: Improper Authentication'
owasp:
- A02:2017 - Broken Authentication
- A07:2021 - Identification and Authentication Failures
- A07:2025 - Authentication Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ANONYMOUS
category: security
technology:
- kotlin
references:
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Improper Authentication
source: https://semgrep.dev/r/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind
shortlink: https://sg.run/rY2n
semgrep.dev:
rule:
r_id: 15125
rv_id: 1263258
rule_id: v8U9Q7
version_id: WrTqKgJ
url: https://semgrep.dev/playground/r/WrTqKgJ/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind
origin: community
message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP
statements. Consider enforcing authentication for LDAP. See https://docs.oracle.com/javase/tutorial/jndi/ldap/auth_mechs.html
for more information.
severity: WARNING
pattern: |
$ENV.put($CTX.SECURITY_AUTHENTICATION, "none")
...
$DCTX = InitialDirContext($ENV, ...)
languages:
- kt
- id: kotlin.lang.security.use-of-sha1.use-of-sha1
message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not
collision resistant and is therefore not suitable as a cryptographic signature.
Use SHA256 or SHA3 instead.
languages:
- kt
severity: WARNING
metadata:
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
cwe:
- 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm'
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
category: security
technology:
- kotlin
references:
- https://owasp.org/Top10/A02_2021-Cryptographic_Failures
subcategory:
- vuln
likelihood: LOW
impact: MEDIUM
confidence: MEDIUM
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/kotlin.lang.security.use-of-sha1.use-of-sha1
shortlink: https://sg.run/N1pp
semgrep.dev:
rule:
r_id: 15127
rv_id: 1263268
rule_id: ZqUOdd
version_id: 2KTv2XZ
url: https://semgrep.dev/playground/r/2KTv2XZ/kotlin.lang.security.use-of-sha1.use-of-sha1
origin: community
pattern-either:
- patterns:
- pattern: |
$VAR = $MD.getInstance("$ALGO")
- metavariable-regex:
metavariable: $ALGO
regex: (SHA1|SHA-1)
- pattern: |
$DU.getSha1Digest().digest(...)
- id: kotlin.lang.security.weak-rsa.use-of-weak-rsa-key
message: RSA keys should be at least 2048 bits based on NIST recommendation.
languages:
- kt
severity: WARNING
metadata:
cwe:
- 'CWE-326: Inadequate Encryption Strength'
owasp:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
- A04:2025 - Cryptographic Failures
source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE
asvs:
section: V6 Stored Cryptography Verification Requirements
control_id: 6.2.5 Insecure Algorithm
control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms
version: '4'
references:
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms
category: security
technology:
- kotlin
subcategory:
- audit
likelihood: HIGH
impact: MEDIUM
confidence: HIGH
license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license
vulnerability_class:
- Cryptographic Issues
source: https://semgrep.dev/r/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key
shortlink: https://sg.run/krq7
semgrep.dev:
rule:
r_id: 15128
rv_id: 1263269
rule_id: nJUZNL
version_id: X0TzypE
url: https://semgrep.dev/playground/r/X0TzypE/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key
origin: community
patterns:
- pattern-either:
- pattern: |
$KEY = $G.getInstance("RSA")
...
$KEY.initialize($BITS)
- metavariable-comparison:
metavariable: $BITS
comparison: $BITS < 2048