github / github/codeql

False negative: unzip using subprocess or `shutil.unpack_archive` is not covered in py/tarslip

Open
#21,712 0 comments 1 reaction 2 assignees Claimed by @hvitved View on GitHub
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

The rule currently misses standard library functions and patterns that perform archive extraction, such as `shutil.unpack_archive` and system `tar` commands invoked via `subprocess`.

https://github.com/positive666/yolo_research/blob/f5795f27a56ca4dbe4c182e12f61309a52e23967/utils/downloads.py#L173
https://github.com/JohnClema/xffl/blob/a920300239a82a85a87d0bf25735762844ee8e9d/aggregator/aggregation.py#L9

Here is a minimal, simplified code example to reproduce:
```python
import tarfile, sys, shutil, zipfile, subprocess
unsafe_filename = sys.argv[1]
tar = tarfile.open(unsafe_filename)
tar.extractall() # detected
# 1. shutil
shutil.unpack_archive(unsafe_filename, "out") # not detected
# 2. subprocess
subprocess.run(["tar", "-xf", unsafe_filename]) # not detected
```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.