Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() except Exception as e: body_text = ""- Confidence
- 93% confidence
- Finding
- The POST target URL is derived from environment-controlled base URLs, and the request can carry sensitive data including phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys. If an attacker can influence environment variables, they can redirect these requests to an attacker-controlled endpoint and exfiltrate credentials or session material.
