Tainted flow: 'CONFIG_PATH' from os.getenv (line 17, credential/environment) → pathlib.Path.write_text (file write)
Medium
- Category
- Data Flow
- Content
def save_config(config): CONFIG_PATH.write_text(json.dumps(config, ensure_ascii=False, indent=2), encoding="utf-8") def auth_set(api_key=None):- Confidence
- 91% confidence
- Finding
- CONFIG_PATH.write_text(json.dumps(config, ensure_ascii=False, indent=2), encoding="utf-8")
