Tainted flow: 'img_url' from requests.get (line 825, network input) → requests.get (network output)
Medium
- Category
- Data Flow
- Content
img_url = result["output"]["results"][0]["url"] logger.info(f"图片 URL: {img_url}") img_response = requests.get(img_url, timeout=30) img_response.raise_for_status() logger.info("通义万相图片生成成功") return img_response.content- Confidence
- 93% confidence
- Finding
- img_response = requests.get(img_url, timeout=30)
