github / github/codeql

JavaScript DOM XSS via fetch().json() → insertAdjacentHTML not detected by CodeQL

Abierto
#21,257 2 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Description of the false positive**

We are trying to better understand the design decisions behind JavaScript XSS detection in CodeQL, specifically around taint sources involving network responses.

I have a piece of client-side JavaScript that builds HTML using `insertAdjacentHTML` with values coming from a fetch().json() response. From an application-security perspective, this is treated as a potential DOM XSS risk in our project, but CodeQL does not report it.

I’d like to confirm whether this behavior is by design, and if so, what the recommended way is to model this trust boundary.

**Code samples or links to source code**

```
function loadMessageLogs(pageSize, continuationToken) {
let url = '?handler=LoadMessageLogs&pageSize=' + pageSize;
if (continuationToken)
url += '&continuationToken=' + encodeURIComponent(continuationToken);

fetch(url)
.then(response => response.json())
.then(data => {
const tbody = document.querySelector("#tblMessageLogs tbody");
tbody.innerHTML = "";

if (!data.items || data.items.length === 0) {
messageLogs.hidden = true;
noMessageLogs.hidden = false;
}
else {

data.items.forEach(item => {
const link = `View message`;
const row = `
${item.createdDate}
${item.messageId}
${item.interfaceId ?? ''}
${item.target ?? ''}
${item.mpanCore ?? ''}
${item.meterId ?? ''}
${link}
`;
tbody.insertAdjacentHTML('beforeend', row);
});

PagingModule.updatePaging(data.continuationToken)
messageLogs.hidden = false;
noMessageLogs.hidden = true;
}
});
}
```

In our case, `data.items[*]` ultimately contains data that may originate from user input stored and returned by the backend.

- We are running the javascript-security-extended query suite.
- No XSS issue is reported for this code.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Comienza con el conjunto de consultas de seguridad-extended de JavaScript y revisa cómo se modelan las respuestas de fetch().json() y insertAdjacentHTML. Determina si este flujo está excluido intencionadamente o si necesita un modelado de fuente y sumidero; después, valida la conclusión con el ejemplo proporcionado y confirma si se espera un resultado de XSS.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
javascript
Área
security
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Necesita aclaración
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.