github / github/codeql

UnvalidatedDynamicMethodCall query does not detect flow inside try/catch

Ouverte
#20,098 3 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
question
Langage dominant
CodeQL
Étoiles
10.1k
Forks
2.1k
Merge moyen
2 j 15 h
PR mergées (30 j)
141

Description

Hi CodeQL team 👋

I'm currently building some training challenges for developers to help them identify insecure dynamic method calls. I designed one of the [exercises](https://github.com/fguisso/backoffice-balm) based on the `UnvalidatedDynamicMethodCall` alert.

However, I noticed that the vulnerability I created was not detected by the query. After a lot of debugging, I suspect the query does not handle taint flow properly when the logic is inside arrow functions.

- The vulnerable code uses an Express route with an arrow function as the handler.
- Inside the arrow function, I access `req.params.action` and use it to dynamically invoke a method: `userManager[action](...)`.
- This allows access to both regular and admin-only methods of the userManager object.

Unfortunately, this pattern wasn't flagged by the query, even though it's clearly unsafe.

I'm still learning how CodeQL queries work, and I'm not very experienced with the query language yet. I'd really appreciate any help understanding why this scenario is missed, and how I might contribute a feature for it.

I'd love to open a PR — just need some guidance on how to proceed the right way.

`update`: I have tested here like @rvermeulen said and the catch is the `try/catch`.

`git blaming` cc: @asgerf

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Start with the UnvalidatedDynamicMethodCall query and reproduce the training challenge linked in the issue. Compare the Express route using req.params.action inside an arrow-function handler with and without try/catch, then confirm that the vulnerable dynamic call is detected when the issue is fixed.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
express, javascript
Domaine
security
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
Plutôt claire
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.