← Home

@contrast/protect

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

tough-griffchrisdunnecontrast_adminjcolekaplancontrastsecmhenry-contrastnbuckwalt

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to established @contrast publisher jcolekaplan (522 approved/0 rejected); benign handoff. ai
semgrep semgrep:etc-passwd-access AI (semgrep): Test fixture strings simulating attack payloads for Protect's detection engine, not real file access. ai
publish-pattern new-deps-added AI (publish-pattern): First-party @contrast/* org packages, consistent with instrumentation architecture. ai
phantom-deps phantom-dep:@contrast/rewriter AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo packages. ai
phantom-deps phantom-dep:@contrast/dep-hooks AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo packages. ai
phantom-deps phantom-dep:@contrast/esm-hooks AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo packages. ai
phantom-deps phantom-dep:@contrast/logger AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo packages. ai
phantom-deps phantom-dep:@contrast/stack-trace-factory AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo packages. ai
phantom-deps phantom-dep:semver AI (phantom-deps): semver is a declared runtime dep; phantom-dep false positive for this package. ai
bogus-package bogus-package AI (bogus-package): Enterprise security agent component; sparse metadata is expected for internal packages. ai
phantom-deps phantom-dep:@contrast/instrumentation AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo packages. ai
phantom-deps phantom-dep:@contrast/scopes AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo packages. ai
phantom-deps phantom-dep:@contrast/patcher AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo packages. ai

Versions (showing 51 of 63)

View all versions
Version Deps Published
1.80.0 16 / 0
1.79.0 16 / 0
1.78.0 16 / 0
1.77.1 16 / 0
1.77.0 16 / 0
1.76.0 16 / 0
1.75.5 16 / 0
1.75.4 16 / 0
1.75.3 16 / 0
1.75.2 16 / 0
1.75.1 16 / 0
1.75.0 16 / 0
1.74.1 16 / 0
1.74.0 16 / 0
1.73.0 16 / 0
1.72.2 15 / 0
1.72.1 15 / 0
1.72.0 15 / 0
1.71.0 15 / 0
1.70.0 15 / 0
1.69.0 15 / 0
1.68.0 15 / 0
1.67.0 15 / 0
1.66.0 15 / 0
1.65.0 15 / 0
1.64.2 15 / 0
1.64.1 15 / 0
1.64.0 15 / 0
1.63.0 15 / 0
1.62.0 15 / 0
1.61.0 15 / 0
1.60.0 15 / 0
1.59.0 15 / 0
1.58.0 15 / 0
1.57.0 15 / 0
1.56.0 15 / 0
1.55.0 15 / 0
1.54.2 15 / 0
1.54.1 15 / 0
1.54.0 15 / 0
1.53.1 15 / 0
1.53.0 15 / 0
1.52.0 15 / 0
1.51.0 14 / 0
1.50.0 13 / 0
1.49.0 13 / 0
1.48.0 13 / 0
1.47.0 13 / 0
1.46.0 13 / 0
1.45.0 13 / 0
1.44.0 13 / 0

v1.80.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.60.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.59.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.58.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.57.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.56.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.55.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.54.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.54.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.54.0

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.53.1

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.53.0

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.52.0

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.51.0

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.50.0

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.49.0

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.48.0

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.47.0

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.46.0

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.45.0

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.44.0

31 findings
HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1281 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1279 | ], 1280 | key: 'hello', > 1281 | value: ';echo put /etc/passwd | tftp host', 1282 | score: 10, 1283 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1297 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1295 | ], 1296 | key: 'hello', > 1297 | value: ';echo put /etc/passwd | tftp host', 1298 | score: 10, 1299 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1313 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1311 | ], 1312 | key: 'hello', > 1313 | value: ';echo put /etc/passwd | tftp host', 1314 | score: 10, 1315 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1329 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1327 | ], 1328 | key: 'hello', > 1329 | value: ';echo put /etc/passwd | tftp host', 1330 | score: 10, 1331 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1347 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1345 | ], 1346 | key: 'hello', > 1347 | value: ';echo put /etc/passwd | tftp host', 1348 | score: 10, 1349 | idsList: [],

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1375 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1373 | ], 1374 | key: 'hello', > 1375 | value: ';echo put /etc/passwd | tftp host', 1376 | score: 10, 1377 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1438 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1436 | ], 1437 | key: 'hello', > 1438 | value: ';echo put /etc/passwd | tftp host', 1439 | score: 10, 1440 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1454 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1452 | ], 1453 | key: 'hello', > 1454 | value: ';echo put /etc/passwd | tftp host', 1455 | score: 10, 1456 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1470 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1468 | ], 1469 | key: 'hello', > 1470 | value: ';echo put /etc/passwd | tftp host', 1471 | score: 10, 1472 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1486 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1484 | ], 1485 | key: 'hello', > 1486 | value: ';echo put /etc/passwd | tftp host', 1487 | score: 10, 1488 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1502 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1500 | ], 1501 | key: 'hello', > 1502 | value: ';echo put /etc/passwd | tftp host', 1503 | score: 90, 1504 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1519 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1517 | ], 1518 | key: 'hello', > 1519 | value: ';echo put /etc/passwd | tftp host', 1520 | score: 90, 1521 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1536 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1534 | ], 1535 | key: 'hello', > 1536 | value: ';echo put /etc/passwd | tftp host', 1537 | score: 90, 1538 | idsList: [

HIGH etc-passwd-access: lib/input-analysis/handlers.test.js:1553 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 1551 | ], 1552 | key: 'hello', > 1553 | value: ';echo put /etc/passwd | tftp host', 1554 | score: 90, 1555 | idsList: [

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:65 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 63 | const sinkContextPositive = { 64 | name: 'fs.readFileSync', > 65 | value: './../../../etc/passwd', 66 | stack: [] 67 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:74 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 72 | }; 73 | const findings = { > 74 | path: './../../../etc/passwd', 75 | }; 76 |

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:83 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 81 | [{ 82 | ruleId: 'path-traversal', > 83 | value: '../../../etc/passwd', 84 | exploitMetadata: [], 85 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:103 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 101 | [{ 102 | ruleId: 'path-traversal', > 103 | value: '../../../etc/passwd', 104 | exploitMetadata: [], 105 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:122 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 120 | [{ 121 | ruleId: 'path-traversal', > 122 | value: '../../../etc/passwd', 123 | exploitMetadata: [], 124 | }],

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:150 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 148 | const sinkContextPositive = { 149 | name: 'child_process.execSync', > 150 | value: 'ls; cat /etc/passwd', 151 | stack: [], 152 | };

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:171 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 169 | [{ 170 | ruleId: 'cmd-injection', > 171 | value: '; cat /etc/passwd', 172 | exploitMetadata: [], 173 | }]

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:191 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 189 | [{ 190 | ruleId: 'cmd-injection', > 191 | value: '; cat /etc/passwd', 192 | exploitMetadata: [], 193 | }], {

HIGH etc-passwd-access: lib/input-tracing/handlers/index.test.js:209 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 207 | [{ 208 | ruleId: 'cmd-injection', > 209 | value: '; cat /etc/passwd', 210 | exploitMetadata: [], 211 | }], {

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:56 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 54 | const sinkContextPositive = { 55 | name: 'child_process.execSync', > 56 | value: 'ls; cat /etc/passwd', 57 | stack: [], 58 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:64 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 62 | stack: [] 63 | }; > 64 | const command = 'ls; cat /etc/passwd'; 65 | 66 | [

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:222 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 220 | const sinkContextPositiveV2 = { 221 | name: 'child_process.execSync', > 222 | value: '/bin/sh -c "cat /etc/passwd"', 223 | stack: [], 224 | };

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:250 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 248 | { 249 | sinkContext: sinkContextPositiveV2, > 250 | exploitMetadata: [{ command: '/bin/sh -c "cat /etc/passwd"' }], 251 | inputType: 'JSON_VALUE', 252 | key: 'command',

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:255 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 253 | path: ['some', 'hidden'], 254 | blocked: false, > 255 | value: '/bin/sh -c "cat /etc/passwd"', 256 | mappedId: Rule.CMD_INJECTION_COMMAND_BACKDOORS, 257 | ruleId: Rule.CMD_INJECTION_COMMAND_BACKDOORS,

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:296 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 294 | headers: ['some-other-header', 'and-its-value', 'malicious-header', 'ls .'] 295 | }; > 296 | sourceContext.parsedBody = { some: { hidden: { command: '-c "cat /etc/passwd"' } } }; 297 | const testFn = () => { 298 | handlers.handleCommandInjectionCommandBackdoors(sourceContext, sinkContextPositive);

HIGH etc-passwd-access: lib/semantic-analysis/handlers.test.js:322 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux 320 | 321 | if (os.platform() !== 'win32') { > 322 | sinkContexts.push({ name: 'fs.readFile', value: '/etc/passwd' }); 323 | } 324 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.