Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() except Exception as e: body_text = ""- Confidence
- 95% confidence
- Finding
- The POST destination is ultimately derived from environment-controlled base URLs, and this helper sends sensitive authentication material such as access tokens, refresh tokens, API tokens, phone numbers, and SMS codes to that destination. In a skill/runtime environment where environment variables can be influenced by a host, wrapper, or attacker, this becomes an SSRF/exfiltration path that can redirect credential-bearing requests to an attacker-controlled server.
