Tainted flow: 'req' from os.environ.get (line 134, credential/environment) → urllib.request.urlopen (network output)
- Category
- Data Flow
- Confidence
- 96% confidence
- Finding
The request URL is derived from BASE_URL, which is taken directly from an environment variable without allowlisting or hostname validation. If an attacker can influence the execution environment, they can redirect the skill’s network call to an arbitrary host, enabling SSRF-style behavior, data exfiltration of queried stock codes, or interaction with internal services; because the code then trusts and parses the returned JSON, it also expands the attack surface to malicious upstream responses.
- Content
python headers={"Accept": "application/json", "User-Agent": "openclaw-skill/1.0"}, ) with urllib.request.urlopen(req, timeout=REQUEST_TIMEOUT) as resp: # HTTPError 会在 urlopen 时抛出,此处只处理读取失败 raw = resp.read().decode("utf-8")
