Tainted flow: 'feedback_log' from os.environ.get (line 1076, credential/environment) → open (file write)
Medium
- Category
- Data Flow
- Content
feedback_log = STORE_DIR / "feedback.log" ensure_dirs() timestamp = datetime.now(timezone.utc).isoformat() with open(feedback_log, "a", encoding="utf-8") as f: f.write(f"\n--- {timestamp} ---\n{message}\n{sys_info}\n") # Build GitHub issue URL- Confidence
- 78% confidence
- Finding
- with open(feedback_log, "a", encoding="utf-8") as f:
