Tainted flow: 'EVENTS_FILE' from os.getenv (line 19, credential/environment) → open (file write)
Medium
- Category
- Data Flow
- Content
def save_events(events): """Save events to JSON file, overwriting.""" ensure_memory_dir() with open(EVENTS_FILE, 'w', encoding='utf-8') as f: json.dump(events, f, indent=2, ensure_ascii=False) def prune_old_events(events, hours=24):- Confidence
- 89% confidence
- Finding
- with open(EVENTS_FILE, 'w', encoding='utf-8') as f:
