Tainted flow: 'MASTER_API_KEY' from os.getenv (line 31, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
def create_api_key() -> str: """Create a new API key using master key""" try: r = requests.post( f"{API_BASE}/b/v1/api-key/create", headers={"Authorization": f"Bearer {MASTER_API_KEY}"}, timeout=30- Confidence
- 98% confidence
- Finding
- r = requests.post( f"{API_BASE}/b/v1/api-key/create", headers={"Authorization": f"Bearer {MASTER_API_KEY}"}, timeout=30 )
