Tainted flow: 'req' from os.environ.get (line 76, credential/environment) → urllib.request.urlopen (network output)
- Category
- Data Flow
- Confidence
- 95% confidence
- Finding
The code allows the network destination to be overridden via the PATENTMAX_BASE_URL environment variable and then sends the API key in an Authorization header to that URL. In an agent or untrusted runtime, an attacker who can influence environment variables can redirect requests and exfiltrate both sensitive patent materials and the bearer token to an attacker-controlled host.
- Content
python req.add_header(key, value) try: with urllib.request.urlopen(req, timeout=TIMEOUT) as response: payload = response.read() return payload if raw else json.loads(payload.decode("utf-8")) except urllib.error.HTTPError as exc:
