Tainted flow: 'url' from os.environ.get (line 36, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
url = f"{BASE_URL}/skill/entData/combinedQuery" headers = {'access_key': ACCESS_KEY} try: response = requests.get(url, headers=headers, params=filtered, verify=True, timeout=30) return response.json() except requests.exceptions.Timeout: return {'code': -1, 'msg': '请求超时'}- Confidence
- 84% confidence
- Finding
- response = requests.get(url, headers=headers, params=filtered, verify=True, timeout=30)
