github / github/codeql

False positive - Incomplete string escaping

Open
#18,379 9 comments 0 reactions 0 assignees View on GitHub
false-positive
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

**Description of the false positive**

```
Incomplete string escaping or encoding
This does not escape backslash characters in the input.
```

```ts
part = `"${part.replace(/"/g, '\\"')}"`;
```

This is intentional,

actual string: `abc\"` -> `"abc\\""`

JS:
```js
'abc\\"' '"abc\\\\""'
```

This code is used in a client library to serialize caller input as-is from list to header value.

```ts
const input = ["a", "b", `\\"`];
const serialized = `a,b,"\\\\""`;
```

**Code samples or links to source code**

https://github.com/smithy-lang/smithy-typescript/blob/d8446cfa3bf6cbcf1187d1ad744ac5a296e442d7/packages/smithy-client/src/quote-header.ts#L8

Contributor guide

Open the contributing guide

Research direction

Start with the linked packages/smithy-client/src/quote-header.ts example and inspect the CodeQL finding that flags its string escaping. Reproduce the report with the provided inputs, then identify the relevant query coverage; done means intentional backslashes in this serialization are no longer reported as incomplete escaping.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.