Tainted flow: 'url' from os.environ.get (line 73, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
"""从远程获取最新版本信息""" url = update_url or DEFAULT_UPDATE_URL try: resp = requests.get(url, timeout=15) resp.raise_for_status() return resp.json() except requests.exceptions.Timeout:- Confidence
- 95% confidence
- Finding
- resp = requests.get(url, timeout=15)
