Tainted flow: 'STATE_FILE' from os.environ.get (line 94, credential/environment) → open (file write)
Medium
- Category
- Data Flow
- Content
def save_state(state): ensure_dirs() with open(STATE_FILE, "w", encoding="utf-8") as f: json.dump(state, f, ensure_ascii=False, indent=2) def load_collections():- Confidence
- 88% confidence
- Finding
- with open(STATE_FILE, "w", encoding="utf-8") as f:
