Tainted flow: 'config' from os.environ.get (line 21, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
return {"error": "未配置 API Key"} try: response = requests.get( f"{config['base_url']}/{task_id}", headers={"Authorization": f"Bearer {config['api_key']}"} )- Confidence
- 93% confidence
- Finding
- response = requests.get( f"{config['base_url']}/{task_id}", headers={"Authorization": f"Bearer {config['api_key']}"} )
