Tainted flow: 'req' from os.environ.get (line 144, credential/environment) → urllib.request.urlopen (network output)
- Category
- Data Flow
- Confidence
- 94% confidence
- Finding
The client builds outbound requests using a base URL taken directly from the PATENTMAX_BASE_URL environment variable and always attaches the Bearer API key before sending. If that environment variable is influenced by an attacker or misconfigured, the tool can exfiltrate the PatentMax API key and user query data to an arbitrary host, which is a real secret-leak and data-exfiltration risk.
- Content
python req.add_header(key, value) try: with urllib.request.urlopen(req, timeout=TIMEOUT) as response: payload = response.read() # 服务端每个响应都回本次实扣和扣完后的余额。记下来,供 _spent/_balance 输出。 # 拿服务端的真值,而不是在本地累加估价:跨进程累加迟早算岔,
