Tainted flow: 'output' from requests.get (line 250, network input) → open (file write)
Medium
- Category
- Data Flow
- Content
if "filename=" in content_disp: output = content_disp.split("filename=")[-1].strip('"').strip("'") with open(output, "wb") as f: for chunk in r.iter_content(chunk_size=8192): f.write(chunk)- Confidence
- 97% confidence
- Finding
- with open(output, "wb") as f:
