Tainted flow: 'SESSION_PATH' from os.environ.get (line 9, credential/environment) → open (file write)
Medium
- Category
- Data Flow
- Content
def save_session(data): with open(SESSION_PATH, 'w', encoding='utf-8') as f: if yaml is None: f.write(dump_yaml_fallback(data)) else:- Confidence
- 94% confidence
- Finding
- with open(SESSION_PATH, 'w', encoding='utf-8') as f:
