Tainted flow: 'headers' from os.getenv (line 164, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
payload.setdefault("options", {})["wait_for_model"] = True try: resp = requests.post(url, headers=headers, json=payload, timeout=timeout) resp.raise_for_status() return resp.json() except requests.exceptions.RequestException as e:- Confidence
- 92% confidence
- Finding
- resp = requests.post(url, headers=headers, json=payload, timeout=timeout)
