Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() except Exception as e: body_text = ""- Confidence
- 89% confidence
- Finding
- The POST target is derived from environment-controlled base URLs and then used to send login and account data with requests.post. In an agent/runtime setting, environment variables are often configurable by deployers or wrappers, so this can redirect phone numbers, SMS codes, access tokens, and API-token operations to attacker-controlled endpoints, creating SSRF and credential exfiltration risk.
