Tainted flow: 'api_url' from os.environ.get (line 133, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
if md_return_image: data["md_image_format"] = md_image_format response = requests.post(api_url, headers=headers, files=files, data=data, timeout=120) if response.status_code == 200: result = response.json()- Confidence
- 97% confidence
- Finding
- response = requests.post(api_url, headers=headers, files=files, data=data, timeout=120)
