Unvalidated Output Injection
- Category
- Output Handling
- Confidence
- 65% confidence
- Finding
Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.
- Content
jsx function UserBio({ bio }) { // This is a classic XSS vulnerability return <div dangerouslySetInnerHTML={{ __html: bio }} />; } ``` * **Command Injection:** Flag any use of shell commands ( e.g. `child_process`, `os.system`) that includes user input directly in the command string.
