Prevent Code Injection
Code injection vulnerabilities occur when an attacker can insert and execute arbitrary code within your application. This includes direct code evaluation (eval, exec), reflection-based attacks, and dynamic method invocation. These vulnerabilities can lead to complete system compromise, data theft, and remote code execution.
Incorrect (Python - eval with user input):
def unsafe(request):
code = request.POST.get('code')
eval(code)Correct (Python - avoid eval entirely, use safe alternatives):
import ast
def safe_parse(user_expr):
# ast.literal_eval only allows literals (strings, numbers, tuples, lists, dicts, booleans, None)
return ast.literal_eval(user_expr)
# For math expressions, use a purpose-built parser instead of evalNote: Avoid
eval()/exec()entirely. Even with hardcoded strings, it normalizes a dangerous pattern. Useast.literal_eval()for parsing data literals, or purpose-built parsers for expressions.
Incorrect (JavaScript - eval with dynamic content):
let dynamic = window.prompt()
eval(dynamic + 'possibly malicious code');
function evalSomething(something) {
eval(something);
}Correct (JavaScript - avoid eval, use safe alternatives):
// Instead of eval for JSON parsing:
const data = JSON.parse(jsonString);
// Instead of eval for dynamic property access:
const value = obj[propertyName];
// Instead of eval for math: use a sandboxed expression parserNote: There is almost never a legitimate reason to use
eval(). UseJSON.parse(), computed property access, or a sandboxed parser. Avoidnew Function()as well — it executes arbitrary code just likeeval().
Incorrect (Java - ScriptEngine injection):
public class ScriptEngineSample {
private static ScriptEngineManager sem = new ScriptEngineManager();
private static ScriptEngine se = sem.getEngineByExtension("js");
public static void scripting(String userInput) throws ScriptException {
Object result = se.eval("test=1;" + userInput);
}
}Correct (Java - static ScriptEngine evaluation):
public class ScriptEngineSample {
public static void scriptingSafe() throws ScriptException {
ScriptEngineManager scriptEngineManager = new ScriptEngineManager();
ScriptEngine scriptEngine = scriptEngineManager.getEngineByExtension("js");
String code = "var test=3;test=test*2;";
Object result = scriptEngine.eval(code);
}
}Incorrect (Ruby - dangerous eval):
b = params['something']
eval(b)
eval(params['cmd'])Correct (Ruby - static eval):
eval("def zen; 42; end")
class Thing
end
a = %q{def hello() "Hello there!" end}
Thing.module_eval(a)Incorrect (PHP - code injection via eval/assert):
$code = $_GET['code'];
eval($code);
$input = $_POST['input'];
assert($input); // assert() evaluates strings as code in PHP < 8.0Correct (PHP - avoid eval, use structured alternatives):
// Instead of eval for dynamic config, use a data format:
$config = json_decode(file_get_contents('config.json'), true);
// Instead of eval for templates, use a template engine (Twig, Blade)Note:
exec()/shell_exec()/system()are OS command execution — see the command-injection rule for those. This rule covers code evaluation viaeval(),assert(),preg_replacewith/e, and similar.
Key Prevention Patterns
- Avoid eval/exec entirely - Use safer alternatives (
JSON.parse,ast.literal_eval, template engines, computed property access) - Never pass user input to code evaluation functions - Treat all user input as untrusted
- If dynamic code execution is unavoidable - Validate against a strict allowlist and sandbox the execution
- Use parameterized alternatives - Most languages offer structured APIs that eliminate the need for eval
For OS command execution (
exec,shell_exec,system) and shell-escaping (escapeshellarg), see the command-injection rule.