Tainted flow: 'req' from os.environ.get (line 76, credential/environment) → urllib.request.urlopen (network output)
- Category
- Data Flow
- Confidence
- 92% confidence
- Finding
The code allows the network destination to be controlled by the PATENTMAX_BASE_URL environment variable, then sends sensitive patent materials and the Bearer API key to that URL via urllib.request.urlopen. If an attacker can influence the environment or deployment configuration, they can redirect requests to an arbitrary host and exfiltrate both credentials and confidential invention disclosures.
- Content
python req.add_header(key, value) try: with urllib.request.urlopen(req, timeout=TIMEOUT) as response: payload = response.read() return payload if raw else json.loads(payload.decode("utf-8")) except urllib.error.HTTPError as exc:
