Tainted flow: 'filename' from input (line 380, user input) → open (file write)
Medium
- Category
- Data Flow
- Content
save = input("\n是否保存结果到文件? (y/n): ").strip().lower() if save == 'y': filename = f"jobs_{keyword}_{city}.txt" with open(filename, 'w', encoding='utf-8') as f: f.write(output) print(f"结果已保存到: {filename}")- Confidence
- 90% confidence
- Finding
- with open(filename, 'w', encoding='utf-8') as f:
