Tainted flow: 'output_path' from input (line 1372, user input) → open (file write)
Medium
- Category
- Data Flow
- Content
if args.output: output_path = os.path.abspath(args.output) with open(output_path, "w", encoding="utf-8") as f: f.write(html) log(f"报告已保存: {output_path}", "OK") else:- Confidence
- 90% confidence
- Finding
- with open(output_path, "w", encoding="utf-8") as f:
