Tainted flow: 'message_file' from os.environ.get (line 311, credential/environment) → open (file write)
Medium
- Category
- Data Flow
- Content
if messages: # 保存到文件 DATA_DIR.mkdir(parents=True, exist_ok=True) with open(message_file, "w", encoding="utf-8") as f: json.dump(messages, f, ensure_ascii=False, indent=2) print(f" 数据已保存到: {message_file}") return messages- Confidence
- 88% confidence
- Finding
- with open(message_file, "w", encoding="utf-8") as f:
