OWASP continues to classify injection flaws as a major application security risk, covering weaknesses such as SQL injection, command injection, and cross-site scripting that arise when untrusted input reaches interpreters without proper validation or sanitization. The guidance emphasizes separating code from data, validating input, and using safe APIs to prevent attackers from altering queries, commands, or application logic.
Semgrep said its taint mode reached beta in v0.70.0, adding lightweight intra-procedural taint analysis to track sources, sanitizers, and sinks more effectively than pattern-only rules for finding injection bugs. The company highlighted use cases including Angular XSS and sandbox code injection, while also pointing developers to common SQL injection pitfalls in Django applications, where the ORM is generally safer by default but raw SQL, custom ORM expressions, and QuerySet.extra() can still expose applications if user input is interpolated instead of passed through parameterized queries.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Semgrep announced that taint mode became officially beta in Semgrep v0.70.0 and said it planned to make the capability generally available on a per-language basis, starting with JavaScript.
The Semgrep blog says taint mode was significantly improved in 2021 Q3, advancing the feature beyond its initial experimental state.
Semgrep's taint mode was introduced experimentally in 2020 as a lightweight intra-procedural taint analysis capability aimed at finding injection vulnerabilities more effectively than pattern-only rules.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.