Static Security Analysis flags CWE-77 thousands of times
22 days ago.
I am a happy user of DayPilot and love it. It is an amazing product. I do have a situation were someone ran a statict security analysis using fortisecdev on version 2025.3.703-lite and found thousands of issues flagged as CWE-77 Improper Neutralization of special elements, but internally it states the errors as generic object injection sink.
Is this a false positive? Do newer versions correct this issue? Anyone else seen something similar? It primarily sees this in file daypilot-month-min.js.
Any help would be greatly appreciated. The tool does not provide any further indications.