Tainted flow: 'req' from os.environ.get (line 281, credential/environment) → urllib.request.urlopen (network output)
- Category
- Data Flow
- Confidence
- 95% confidence
- Finding
The code sends diagnostic data to a remote endpoint whose URL is controlled by the PDD_BUG_REPORT_URL environment variable, allowing outbound transmission to an arbitrary host. Although the payload is intended to be minimal, this creates an exfiltration channel and expands behavior beyond local sync; in this shop-data context, unexpected outbound reporting is especially sensitive because it occurs in software handling merchant account data and operational metadata.
- Content
python req = urllib.request.Request( REPORT_URL, data=payload, method="POST", headers={"Content-Type": "application/json"}) with urllib.request.urlopen(req, timeout=3) as r: resp = json.loads(r.read().decode() or "{}") s = _load()
