Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() except Exception as e: body_text = ""- Confidence
- 92% confidence
- Finding
- The code builds request destinations from environment-controlled base URLs and then sends sensitive authentication material such as access tokens, API keys, phone numbers, and SMS codes to those endpoints via requests.post. If an attacker can influence environment variables, this becomes credential exfiltration or SSRF-to-attacker infrastructure, and the risk is amplified because this onboarding script handles login and token issuance rather than the advertised Ozon shop-search function.
