False positive: js/incomplete-hostname-regexp treats LinkifyIt.match(text) as a regex call

Aperta
#22,546 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
55/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
javascript
Ambito
security

Direzione di ricerca

Esamina la query js/incomplete-hostname-regexp e i relativi modelli di libreria, quindi confronta il precedente di Sinon in PR 19854. Riesegui l’alert di CodeQL collegato su test/link-recognition-qualification.test.js; il lavoro è completato quando i literal di LinkifyIt.match(text) non vengono più segnalati, mentre i normali risultati regex di String.match rimangono abilitati.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Description of the false positive

js/incomplete-hostname-regexp treats the argument to LinkifyIt.match(text) as a regular expression. The receiver is a LinkifyIt instance from linkify-it@6.1.0; its argument is document text to scan for links, not a regex pattern. Literal dots in these URLs are therefore correct.

Observed with CodeQL 2.26.4, JavaScript/TypeScript analysis, build-mode: none, and github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938 (v4.37.9), using the default query suite without custom queries or exclusions.

Diagnostic on the text literal:

This string, which is used as a regular expression here, has an unescaped '.' before 'youtube.com/watc', so it might match more hosts than expected.

The linked use is scanner.match(text).

Code samples or links to source code

Small excerpt retaining the constructor, configuration, literal and call from the reported test:

import { LinkifyIt } from "linkify-it";

const scanner = new LinkifyIt({ fuzzyLink: false, fuzzyEmail: false })
  .add("ftp:", null)
  .add("mailto:", null)
  .add("//", null);
const text =
  "😀 *literal* (https://www.youtube.com/watch?v=tax4e4hBBZc), then https://store.steampowered.com/app/457140/.";
const matches = scanner.match(text);
console.log(matches.map((m) => m.raw));

With linkify-it@6.1.0, the API returns matches for the two literal URLs. The package's build/index.d.ts declares match(text: string): Match[] | null; build/index.mjs implements the method by scanning that document text with the library's link recognizers.

Exact reported source at the PR merge revision.

Source at the immutable PR head.

Validation: node --test test/link-recognition-qualification.test.js passes 1/1, including exact URL and offset assertions. The hosted CodeQL analysis reports the finding in the linked full test. The reduced excerpt above has not been separately analyzed with CodeQL; no claim is made that it is the smallest scanner reproducer.

Expected: recognize that this imported library's match method consumes document text, so these literals should not be classified as hostname regular expressions. Ordinary String.match regex findings should remain enabled.

Related precedent: https://github.com/github/codeql/pull/19854 explicitly models Sinon's match calls as non-RegExp. I found no existing linkify-it report in the upstream search.

URL to the alert on GitHub code scanning (optional)

https://github.com/MaksymShostak/steam-community-bbcode/security/code-scanning/2

Failing PR check.

Lingua principale
CodeQL
Stelle
10.1k
Fork
2.1k
Merge medio
2g 11h
PR unite (30g)
129

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di github/codeql

Tutte le issue di github/codeql

Issue simili

Altre issue su Security

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.