Tainted flow: 'url' from os.environ.get (line 61, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
'model': 'image-01', 'prompt': prompt } resp = requests.post(url, headers=headers, json=payload, timeout=60) if resp.status_code != 200: return {"error": f"API error {resp.status_code}: {resp.text[:200]}"}- Confidence
- 93% confidence
- Finding
- resp = requests.post(url, headers=headers, json=payload, timeout=60)
