Tainted flow: 'API_BASE' from os.getenv (line 23, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
if seed is not None: payload["seed"] = seed resp = requests.post( f"{API_BASE}/image_generation", headers=_headers(), json=payload,- Confidence
- 90% confidence
- Finding
- resp = requests.post( f"{API_BASE}/image_generation", headers=_headers(), json=payload, timeout=120, )
