Skip to content

Commit 3a4ea82

Browse files
Update javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.ql
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
1 parent 8310c96 commit 3a4ea82

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,11 +25,11 @@ abstract class ServerSideTemplateInjectionSink extends DataFlow::Node { }
2525

2626
class SSTIPugSink extends ServerSideTemplateInjectionSink {
2727
SSTIPugSink() {
28-
exists(CallNode compile, ModuleImportNode renderImport, Node sink |
28+
exists(CallNode compile, ModuleImportNode renderImport |
2929
renderImport = moduleImport(["pug", "jade"]) and
3030
(
3131
compile = renderImport.getAMemberCall("compile") and
32-
sink.getStartLine() != sink.getASuccessor().getStartLine()
32+
exists(compile.getACall())
3333
or
3434
compile = renderImport.getAMemberCall("render")
3535
) and

0 commit comments

Comments
 (0)