Tainted flow: 'API_URL' from os.getenv (line 7, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
"stream": True } response = requests.post(API_URL, headers=headers, json=payload, timeout=180, stream=True) if response.status_code != 200: print(f"HTTP {response.status_code}: {response.text}", file=sys.stderr)- Confidence
- 97% confidence
- Finding
- response = requests.post(API_URL, headers=headers, json=payload, timeout=180, stream=True)
