Tainted flow: 'index_file' from os.environ.get (line 117, credential/environment) → open (file write)
Medium
- Category
- Data Flow
- Content
kept.append(s) index["sessions"] = kept with open(index_file, "w", encoding="utf-8") as f: json.dump(index, f, ensure_ascii=False, indent=2) print(f"[ultra-memory] session_index.json: {original_count} → {len(kept)} 条记录")- Confidence
- 88% confidence
- Finding
- with open(index_file, "w", encoding="utf-8") as f:
