Tainted flow: 'gateway_url' from os.environ.get (line 35, credential/environment) → requests.patch (network output)
Critical
- Category
- Data Flow
- Content
headers = {} if token: headers["Authorization"] = f"Bearer {token}" resp = requests.patch(f"{gateway_url}/api/config", headers=headers, json=payload, timeout=5) return resp.ok except Exception:- Confidence
- 93% confidence
- Finding
- The code sends the supplied API key and optional bearer token to a URL taken directly from the OPENCLAW_GATEWAY_URL environment variable with no validation of scheme, host, or trust boundary. If that environment variable is tampered with, secrets can be exfiltrated to an attacker-controlled endpoint, and the default uses plain HTTP, which further exposes credentials to interception on non-local deployments.
