Tainted flow: 'output_file' from input (line 228, user input) → open (file write)
Medium
- Category
- Data Flow
- Content
output_dir = os.path.dirname(os.path.dirname(os.path.abspath(__file__))) output_file = os.path.join(output_dir, f"讲解词_{relic_name}.txt") with open(output_file, "w", encoding="utf-8") as f: f.write(narration) return output_file- Confidence
- 97% confidence
- Finding
- with open(output_file, "w", encoding="utf-8") as f:
