Tainted flow: 'image_url' from requests.post (line 114, network input) → requests.get (network output)
Medium
- Category
- Data Flow
- Content
print(f"\n图片URL: {image_url}") # 下载图片 img_resp = requests.get(image_url, timeout=60) with open(output_path, "wb") as f: f.write(img_resp.content) print(f"已保存: {output_path}")- Confidence
- 91% confidence
- Finding
- img_resp = requests.get(image_url, timeout=60)
