Skip to content

VBC-004: sql-injection-concatenation ​

error

Category: security
Analysis: Regex (line by line)
File types: .js, .ts, .tsx, .jsx, .py, .go, .php, .rb, .java, .cs, .astro
Scope: the whole file, with no scope filtering
Excluded paths: **/test/**, **/tests/**, **/__tests__/**, **/testdata/**, **/fixtures/**, **/test_*.py, **/*_test.py, **/test.py, **/conftest.py, **/*_test.go, **/*.test.*, **/*.spec.*
Tags: security

What it reports ​

SQL built by string concatenation at line {line}. An attacker controlling the interpolated value can rewrite the statement. Use parameterized queries or a query builder that binds values separately.

Flagged ​

js
db.query("SELECT * FROM users WHERE id = " + id);
js
sql += " AND status = " + status;
js
sql += " WHERE name = " + name;
js
q = "SELECT id FROM t WHERE id IN (" + ids + ")"

Not flagged ​

js
q += " ORDER BY acquired DESC;"
js
q += " LIMIT 10;"
js
db.query("SELECT * FROM users WHERE id = $1", [id]);
js
q += ` AND project = ?`
js
sql += " AND id = $1"
js
sql += " AND name = :name"
js
const label = 'Update ' + count + ' items';
js
const hint = '<p>Select where your domains are managed</p>' + extra;
js
console.log(`render bench (${where}, ${secs}s` + tail);
go
db.Exec("DELETE FROM " + table)

Pattern ​

regex
(?:"[^"\n]*|'[^'\n]*|`[^`\n]*)(?:\bSELECT\b[^\n]{0,80}?\bFROM\b|\bINSERT\s+INTO\b|\bUPDATE\b[^\n]{0,80}?\bSET\b|\bDELETE\b[^\n]{0,80}?\bFROM\b|\bWHERE\s+[A-Za-z_][\w.]*\s*(?:=|<>|!=|<|>|\b(?:IN|LIKE|IS|BETWEEN)\b)|\bVALUES\s*\()[^\n]{0,120}?["'`]\s*\+|\+=?\s*(?=[^\n]*["'`]\s*\+)["'`][^\n]{0,80}?\b(?:WHERE\s|VALUES\s*\(|SET\s+\w+\s*=(?!\s*(?:\?|\$\d+|:\w+|%[sd])\s*[\"'`])|ORDER\s+BY|GROUP\s+BY|LIMIT\s+\d|AND\s+\w+\s*=(?!\s*(?:\?|\$\d+|:\w+|%[sd])\s*[\"'`])|OR\s+\w+\s*=(?!\s*(?:\?|\$\d+|:\w+|%[sd])\s*[\"'`]))

Released under the MIT License.