CodeQL library for JavaScript/TypeScript
codeql/javascript-all 2.6.3 (changelog, source)
Search

Predicate UnsafeDynamicMethodAccess::FlowState::unsafeFunction

A reference to an unsafe function, such as eval, obtained by reading from a tainted property name.

Import path

import semmle.javascript.security.dataflow.UnsafeDynamicMethodAccessCustomizations
FlowState unsafeFunction()