Tainted flow: 'req' from os.environ.get (line 67, credential/environment) → urllib.request.urlopen (network output)
Critical
- Category
- Data Flow
- Content
full_url = f"{url}?{urllib.parse.urlencode(params)}" req = urllib.request.Request(full_url) with urllib.request.urlopen(req, timeout=10) as response: data = json.loads(response.read().decode()) for item in data.get("items", []):- Confidence
- 94% confidence
- Finding
- with urllib.request.urlopen(req, timeout=10) as response:
