Tainted flow: 'headers' from os.environ.get (line 55, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
"messages": [{"role": "user", "content": prompt}], "max_tokens": 1200, } r = requests.post( f"{OPENAI_BASE_URL}/chat/completions", headers=headers, json=payload,- Confidence
- 92% confidence
- Finding
- r = requests.post( f"{OPENAI_BASE_URL}/chat/completions", headers=headers, json=payload, timeout=60, )
