🔥 3-day streak
GitHub Advanced Security (GH-500)22 / 144
Question 22 of 144

A security engineer is reviewing a CodeQL alert flagged as 'SQL query built from user-controlled sources'. The alert view shows a series of connected steps from an HTTP request parameter through several variable assignments and finally into a database execution call. A developer argues the alert is a false positive because the input is validated. Which aspect of the CodeQL alert should the engineer examine to determine whether the reported vulnerability path is actually exploitable?

Reviewed for accuracy · Report an issueNext question