Tainted flow: 'url' from os.environ.get (line 114, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
url = f"{BINANCE_FUTURES_API}{endpoint}?{query}&signature={signature}" headers = {'X-MBX-APIKEY': API_KEY} if method == 'GET': r = requests.get(url, headers=headers, timeout=10) elif method == 'POST': r = requests.post(url, headers=headers, timeout=10) elif method == 'DELETE':- Confidence
- 97% confidence
- Finding
- r = requests.get(url, headers=headers, timeout=10)
