UNPKG

mcp-server-semgrep

Version:

MCP Server for Semgrep Integration - static code analysis with AI

38 lines (37 loc) 1.43 kB
rules: - id: require-request message: >- If an attacker controls the x in require(x) then they can cause code to load that was not intended to run on the server. severity: LOW languages: [javascript, typescript] metadata: owasp: "A03:2021 - Injection" cwe: "CWE-706: Use of Incorrectly-Resolved Name or Reference" source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html category: security likelihood: lOW # ruleid: metadata-impact-incorrect-value impact: lOW technology: - express references: - https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it patterns: - id: require-request message: >- If an attacker controls the x in require(x) then they can cause code to load that was not intended to run on the server. severity: LOW languages: [javascript, typescript] metadata: owasp: "A03:2021 - Injection" cwe: "CWE-706: Use of Incorrectly-Resolved Name or Reference" source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html category: security # ok: metadata-impact-incorrect-value impact: LOW likelihood: LOW technology: - express references: - https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it patterns: