github / github/codeql

False positive - DOMParser().parseFromString is treated as XSS sink

Đang mở
#12,882 0 bình luận 2 reaction 0 người được giao Xem trên GitHub
false-positive JS
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

**Description of the false positive**

CodeQL considers `DOMParser().parseFromString` as XSS sink but I think it is no longer XSS sink.

Though there was a bug in Safari some years ago, but the method is designed not to execute JavaScript as far as I read the discussions in https://github.com/GoogleChrome/web.dev/issues/6890 and the spec.

https://html.spec.whatwg.org/multipage/dynamic-markup-insertion.html#dom-domparser-parsefromstring-dev
> Note that [script](https://html.spec.whatwg.org/multipage/scripting.html#the-script-element) elements are not evaluated during parsing, and the resulting document's [encoding](https://dom.spec.whatwg.org/#concept-document-encoding) will always be [UTF-8](https://encoding.spec.whatwg.org/#utf-8).

**Code samples or links to source code**

https://github.com/microsoft/vscode/blob/57bceb67381bd630e4e7bac7a8ea170fd2f0b01e/extensions/markdown-language-features/preview-src/index.ts#L133-L134

https://github.com/github/codeql/blob/b6a7661c7e81ae296d92fe93c974910d9a479065/javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss/tst.js#L177-L180

**URL to the alert on GitHub code scanning (optional)**

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.