Tainted flow: 'req' from os.environ.get (line 189, credential/environment) → urllib.request.urlopen (network output)
- Category
- Data Flow
- Confidence
- 90% confidence
- Finding
The request destination is derived from BASE_URL, which is taken from the PATENTMAX_BASE_URL environment variable, and the code sends sensitive material including API-derived authentication and user-provided business context to that endpoint. If an attacker can influence the environment, they can redirect traffic to an arbitrary host and capture the issued trial key workflow or submitted data, creating SSRF-like exfiltration and credential leakage risk.
- Content
python req.add_header("Content-Type", "application/json") req.add_header("Accept", "application/json") try: with urllib.request.urlopen(req, timeout=30) as response: payload = json.loads(response.read().decode("utf-8")) except urllib.error.HTTPError as exc: message = _server_message(exc.read().decode("utf-8", "replace"))
