Tainted flow: 'req' from os.environ.get (line 133, credential/environment) → urllib.request.urlopen (network output)
- Category
- Data Flow
- Confidence
- 90% confidence
- Finding
The script fetches attacker-controlled evidence URLs with urllib.request.urlopen after only checking that they begin with https://. This creates a server-side request forgery risk: a user or upstream agent can make the tool contact arbitrary HTTPS endpoints, including internal services or cloud metadata-like endpoints exposed behind HTTPS, and can also cause large or slow downloads because there are no host allowlists or size limits.
- Content
python if not url.startswith("https://"): raise Refused(f"evidence must be an https URL: {url}") req = urllib.request.Request(url, headers={"User-Agent": UA}) with urllib.request.urlopen(req, timeout=120) as r: return r.read()
