Tainted flow: 'url' from os.getenv (line 119, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
"Name": "Ability.AovAbility" } response = requests.post(url, headers=headers, json=body, timeout=30) result = response.json() if result.get("code") != 2000:- Confidence
- 94% confidence
- Finding
- response = requests.post(url, headers=headers, json=body, timeout=30)
