UNPKG

mcp-server-semgrep

Version:

MCP Server for Semgrep Integration - static code analysis with AI

37 lines (36 loc) 1.38 kB
rules: - id: require-request message: >- If an attacker controls the x in require(x) then they can cause code to load that was not intended to run on the server. severity: LOW languages: [javascript, typescript] # ok: metadata-impact metadata: owasp: "A03:2021 - Injection" cwe: "CWE-706: Use of Incorrectly-Resolved Name or Reference" source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html category: security likelihood: LOW impact: LOW confidence: LOW technology: - express references: - https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it patterns: - id: require-request message: >- If an attacker controls the x in require(x) then they can cause code to load that was not intended to run on the server. severity: LOW languages: [javascript, typescript] # ruleid: metadata-impact metadata: owasp: "A03:2021 - Injection" cwe: "CWE-706: Use of Incorrectly-Resolved Name or Reference" source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html category: security technology: - express references: - https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it patterns: