Tainted flow: 'OAUTH_BASE_URL' from os.environ.get (line 31, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
_delete_credentials() resp = requests.post( f"{OAUTH_BASE_URL}/oauth/api/device/init", json={ "client_id": CLIENT_ID- Confidence
- 90% confidence
- Finding
- resp = requests.post( f"{OAUTH_BASE_URL}/oauth/api/device/init", json={ "client_id": CLIENT_ID }, headers={"Monimaster-Device-Ty
