JavaScript DOM XSS via fetch().json() → insertAdjacentHTML not detected by CodeQL
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 需要澄清
- 活跃度
- 停滞
- 技术栈
- javascript
- 领域
- security
调研方向
从 JavaScript security-extended 查询套件开始,检查 fetch().json() 响应和 insertAdjacentHTML 是如何建模的。确定此流是否被有意排除,还是需要对源和汇进行建模,然后根据提供的示例验证结论,并确认是否预期会得到 XSS 结果。
由索引模型根据 Issue 内容生成。
描述
Description of the false positive
We are trying to better understand the design decisions behind JavaScript XSS detection in CodeQL, specifically around taint sources involving network responses.
I have a piece of client-side JavaScript that builds HTML using insertAdjacentHTML with values coming from a fetch().json() response. From an application-security perspective, this is treated as a potential DOM XSS risk in our project, but CodeQL does not report it.
I’d like to confirm whether this behavior is by design, and if so, what the recommended way is to model this trust boundary.
Code samples or links to source code
function loadMessageLogs(pageSize, continuationToken) {
let url = '?handler=LoadMessageLogs&pageSize=' + pageSize;
if (continuationToken)
url += '&continuationToken=' + encodeURIComponent(continuationToken);
fetch(url)
.then(response => response.json())
.then(data => {
const tbody = document.querySelector("#tblMessageLogs tbody");
tbody.innerHTML = "";
if (!data.items || data.items.length === 0) {
messageLogs.hidden = true;
noMessageLogs.hidden = false;
}
else {
data.items.forEach(item => {
const link = `<a href="/MessageLogs/Details/${item.messageId}">View message</a>`;
const row = `<tr>
<td>${item.createdDate}</td>
<td>${item.messageId}</td>
<td>${item.interfaceId ?? ''}</td>
<td>${item.target ?? ''}</td>
<td>${item.mpanCore ?? ''}</td>
<td>${item.meterId ?? ''}</td>
<td>${link}</td>
</tr>`;
tbody.insertAdjacentHTML('beforeend', row);
});
PagingModule.updatePaging(data.continuationToken)
messageLogs.hidden = false;
noMessageLogs.hidden = true;
}
});
}
In our case, data.items[*] ultimately contains data that may originate from user input stored and returned by the backend.
- We are running the javascript-security-extended query suite.
- No XSS issue is reported for this code.
- 主要语言
- CodeQL
- 星标
- 10.1k
- 派生
- 2.1k
- 平均合并
- 2 天 16 小时
- 30 天内合并 PR
- 143
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/codeql 的其他 Issue
-
agentic-workflows
难度 2/5 1-3 小时 新手友好度 70/100
-
false-positive javascript
难度 2/5 1-3 小时 新手友好度 84/100
-
难度 2/5 1-3 小时 新手友好度 82/100
-
难度 2/5 1-3 小时 新手友好度 78/100
-
false-positive
难度 2/5 1-3 小时 新手友好度 70/100
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 75/100
docToolchain/docToolchain#1705 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
modelcontextprotocol/python-sdk#3566 ·
-
Mend: dependency security vulnerability status: needs triage 🕵️♀️
难度 2/5 1-3 小时 新手友好度 70/100
carbon-design-system/ibm-products#9907 ·
-
agent/security hive/hosted-available-lke648397-260827-5n31 security
难度 2/5 1-3 小时 新手友好度 75/100
-
enhancement
难度 2/5 1-3 小时 新手友好度 70/100
canonical/paas-charm#368 · 1 条评论 ·