github / github/codeql

False positive - DOMParser().parseFromString is treated as XSS sink

オープン
#12,882 コメント 0 件 リアクション 2 件 担当者 0 名 GitHub で見る
false-positive JS
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

**Description of the false positive**

CodeQL considers `DOMParser().parseFromString` as XSS sink but I think it is no longer XSS sink.

Though there was a bug in Safari some years ago, but the method is designed not to execute JavaScript as far as I read the discussions in https://github.com/GoogleChrome/web.dev/issues/6890 and the spec.

https://html.spec.whatwg.org/multipage/dynamic-markup-insertion.html#dom-domparser-parsefromstring-dev
> Note that [script](https://html.spec.whatwg.org/multipage/scripting.html#the-script-element) elements are not evaluated during parsing, and the resulting document's [encoding](https://dom.spec.whatwg.org/#concept-document-encoding) will always be [UTF-8](https://encoding.spec.whatwg.org/#utf-8).

**Code samples or links to source code**

https://github.com/microsoft/vscode/blob/57bceb67381bd630e4e7bac7a8ea170fd2f0b01e/extensions/markdown-language-features/preview-src/index.ts#L133-L134

https://github.com/github/codeql/blob/b6a7661c7e81ae296d92fe93c974910d9a479065/javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss/tst.js#L177-L180

**URL to the alert on GitHub code scanning (optional)**

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。