Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() except Exception as e: body_text = ""- Confidence
- 95% confidence
- Finding
- The POST destination is derived from environment-controlled base URLs, and this function sends sensitive login material such as phone numbers, SMS codes, access tokens, and refresh tokens to those endpoints. If an attacker can influence environment variables, they can redirect these requests to attacker-controlled infrastructure and exfiltrate credentials and session tokens.
