Tainted flow: 'files' from requests.get (line 141, network input) → requests.post (network output)
Medium
- Category
- Data Flow
- Content
try: with open(image_path, "rb") as f: files = {"media": (filename, f, content_type)} resp = requests.post(url, files=files, timeout=30) data = resp.json() if "url" in data:- Confidence
- 90% confidence
- Finding
- resp = requests.post(url, files=files, timeout=30)
