github / github/codeql

False positive - DOMParser().parseFromString is treated as XSS sink

Aberta
#12,882 0 comentários 2 reações 0 responsáveis Ver no GitHub
false-positive JS
Linguagem predominante
CodeQL
Estrelas
10.1k
Forks
2.1k
Merge médio
2d 15h
PRs com merge (30d)
141

Descrição

**Description of the false positive**

CodeQL considers `DOMParser().parseFromString` as XSS sink but I think it is no longer XSS sink.

Though there was a bug in Safari some years ago, but the method is designed not to execute JavaScript as far as I read the discussions in https://github.com/GoogleChrome/web.dev/issues/6890 and the spec.

https://html.spec.whatwg.org/multipage/dynamic-markup-insertion.html#dom-domparser-parsefromstring-dev
> Note that [script](https://html.spec.whatwg.org/multipage/scripting.html#the-script-element) elements are not evaluated during parsing, and the resulting document's [encoding](https://dom.spec.whatwg.org/#concept-document-encoding) will always be [UTF-8](https://encoding.spec.whatwg.org/#utf-8).

**Code samples or links to source code**

https://github.com/microsoft/vscode/blob/57bceb67381bd630e4e7bac7a8ea170fd2f0b01e/extensions/markdown-language-features/preview-src/index.ts#L133-L134

https://github.com/github/codeql/blob/b6a7661c7e81ae296d92fe93c974910d9a479065/javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss/tst.js#L177-L180

**URL to the alert on GitHub code scanning (optional)**

Guia de contribuição

Abrir o guia de contribuição

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.