github / github/codeql

False positive for Prototype-polluting function

Ouverte
#18,327 4 commentaires 1 réaction 0 personnes assignées Voir sur GitHub
false-positive javascript
Langage dominant
CodeQL
Étoiles
10.1k
Forks
2.1k
Merge moyen
2 j 15 h
PR mergées (30 j)
141

Description

I check for prototype polluting property keys in a set of reserved keys which include `__proto__` and `constructor`.

This shouldn't even be necessary since the key, value come from Object.entries which according to MDN will only iterate own enumerable string-keyd property. ie. never `__proto__` or `constructor`.

https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Object/entries

![image](https://github.com/user-attachments/assets/55d3c365-db31-4132-b528-b147cddb6043)

Still the lookup in the set does not work.

```js
// Iterate through the source own enumerable string-keyed property key-value pairs.
for (const [key, value] of Object.entries(source)) {

// This for codeql only. key, value of Object.entries should ensure that only own properties are parsed
if (!source.hasOwnProperty(key)) continue;

// The ignoreKeys contain checks against prototype pollution.
if (new Set(['__proto__', 'constructor', 'mapview']).has(key)) {

continue;
}
```

CodeQL looks at the right place but ignores the check for the set.

https://github.com/GEOLYTIX/xyz/security/code-scanning/217

![image](https://github.com/user-attachments/assets/d1cfd2a3-fde5-439e-b3b2-cc82ae87694e)

The only way I can make the issue go away is by doing a === check on the string value like so.

```js
// Prevent prototype polluting assignment.
if (key === '__proto__' || key === 'constructor') return true;
```

Even though I know that this issue can not happen I need to add this extra line to make the CodeQL warning go away.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Start with the linked CodeQL code-scanning alert and the reported JavaScript snippet; no repository file or test is named. Trace how the relevant query handles Object.entries and Set membership, then add or update regression coverage so this false positive is no longer reported.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
javascript
Domaine
security
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
À clarifier
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.