Tainted flow: 'audio_url' from os.getenv (line 90, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
audio_url = output['audio']['url'] # 下载音频 audio_response = requests.get(audio_url, timeout=60) if audio_response.status_code == 200: with open(output_file, "wb") as f: f.write(audio_response.content)- Confidence
- 91% confidence
- Finding
- audio_response = requests.get(audio_url, timeout=60)
