3 ms·
Interesting. You can try it out here: https://semgrep.dev/editor/ https://semgrep.dev/editor/ It doesn't appear to catch the following when searching for exec(
by scanr 6y ago
Interesting. You can try it out here: https://semgrep.dev/editor/ https://semgrep.dev/editor/
It doesn't appear to catch the following when searching for exec(...) in the following python code:
not_exec = exec
not_exec('rm -rf /')
Edited to include language
- deleted 6y ago[deleted]
- ievans 6y agoGood catch. Currently we only support constant propagation for literals. Here's a working example: $ semgrep -e "not_exec('somestr)" will match foo = "somestr" not_exec(foo) Here's a more complete example: https://semgrep.dev/s/ievans:const-python https://semgrep.dev/s/ievans:const-python In your example, we don't propagate exec because it's not seen as a literal -- that's a TODO for sure. See https://github.com/returntocorp/semgrep/issues/1645 https://github.com/returntocorp/semgrep/issues/1645 for a longer discussion!