Tainted flow: 'BEHAVIOR_FILE' from os.environ.get (line 16, credential/environment) → open (file write)
Medium
- Category
- Data Flow
- Content
"""保存行为数据""" data["last_updated"] = datetime.now().isoformat() BEHAVIOR_FILE.parent.mkdir(parents=True, exist_ok=True) with open(BEHAVIOR_FILE, 'w') as f: json.dump(data, f, indent=2, ensure_ascii=False) def extract_from_memory(date_str=None):- Confidence
- 91% confidence
- Finding
- with open(BEHAVIOR_FILE, 'w') as f:
