-
Notifications
You must be signed in to change notification settings - Fork 0
Description
Code Security Report
Scan Metadata
Latest Scan: 2025-06-29 11:47am
Total Findings: 4 | New Findings: 0 | Resolved Findings: 0
Tested Project Files: 70
Detected Programming Languages: 1 (JavaScript / TypeScript*)
- Check this box to manually trigger a scan
Finding Details
| Severity | Vulnerability Type | CWE | File | Data Flows | Detected | ||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Command Injection | 1 | 2025-06-29 11:47am | |||||||||||||||||||||||
| |||||||||||||||||||||||||
| var done; | |
| done = this.async(); | |
| var cmd = process.platform === "win32" ? "NODE_ENV=" + finalEnv + " & " : "NODE_ENV=" + finalEnv + " "; | |
| exec( |
1 Data Flow/s detected
Line 151 in 44c6716
| var finalEnv = process.env.NODE_ENV || arg || "development"; |
Line 155 in 44c6716
| var cmd = process.platform === "win32" ? "NODE_ENV=" + finalEnv + " & " : "NODE_ENV=" + finalEnv + " "; |
Line 158 in 44c6716
| cmd + "node artifacts/db-reset.js", |
Line 157 in 44c6716
| exec( |
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Command Injection Training
● Videos
▪ Secure Code Warrior Command Injection Video
● Further Reading
🏴 Suppress Finding
- ... as False Alarm
- ... as Acceptable Risk
Vulnerable Code
NodeGoat/test/security/profile-test.js
Line 25 in 44c6716
| var zaproxy = new ZapClient(zapOptions); |
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Hardcoded Password/Credentials Training
● Videos
🏴 Suppress Finding
- ... as False Alarm
- ... as Acceptable Risk
Vulnerable Code
NodeGoat/test/security/profile-test.js
Line 37 in 44c6716
| var sutUserPassword = "User1_123"; |
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Hardcoded Password/Credentials Training
● Videos
🏴 Suppress Finding
- ... as False Alarm
- ... as Acceptable Risk
Vulnerable Code
Lines 73 to 78 in 44c6716
| // Mandatory in Express v4 | |
| extended: false | |
| })); | |
| // Enable session management using express middleware | |
| app.use(session({ |
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Sensitive Cookie Without Secure Training
● Videos
🏴 Suppress Finding
- ... as False Alarm
- ... as Acceptable Risk