CodeQL Alert #43: Reflected server-side cross-site scripting
| Field |
Value |
| Rule ID |
py/reflective-xss |
| Severity |
MEDIUM |
| File path |
vulnerable_ssrf.py |
| Line range |
Lines 49–49 |
| CWE category |
CWE-079, CWE-116 |
| Classification |
demo-only |
| Priority tier |
batched |
| Alert link |
View CodeQL Alert |
Code Snippet
metadata = requests.get(metadata_url, timeout=5).json()
return metadata
def download_file(file_url):
response = requests.get(file_url, stream=True)
Classification: demo-only
This file is prefixed with vulnerable_ and is an intentionally insecure demo file for CodeQL demonstration purposes.
Generated by automated security triage on 2026-03-25.
CodeQL Alert #43: Reflected server-side cross-site scripting
py/reflective-xssvulnerable_ssrf.pydemo-onlybatchedCode Snippet
metadata = requests.get(metadata_url, timeout=5).json() return metadata def download_file(file_url): response = requests.get(file_url, stream=True)Classification:
demo-onlyThis file is prefixed with
vulnerable_and is an intentionally insecure demo file for CodeQL demonstration purposes.Generated by automated security triage on 2026-03-25.