Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() except Exception as e: body_text = ""- Confidence
- 93% confidence
- Finding
- The code builds POST destinations from environment-configurable base URLs and then sends sensitive data such as phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys to those endpoints. If an attacker can influence environment variables, they can redirect authentication traffic and credentials to an arbitrary server, effectively turning this onboarding script into an exfiltration channel.
