Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)
- Category
- Data Flow
- Confidence
- 96% confidence
- Finding
The client allows the destination host to be overridden from an environment variable, CLI flag, or config file, then sends the Bearer API key to that host in every request. If an attacker can influence A7W_HOST or the saved config, they can redirect requests to an attacker-controlled server and exfiltrate the credential; in an agent/platform setting, environment-variable control is a realistic threat boundary issue.
- Content
python headers["Content-Type"] = "application/json" req = urllib.request.Request(url, data=data, headers=headers, method=method) try: with urllib.request.urlopen(req, timeout=timeout) as resp: raw = resp.read().decode("utf-8", "replace") status = resp.status except urllib.error.HTTPError as exc:
