Tainted flow: 'upload_url' from requests.post (line 96, network input) → requests.put (network output)
Medium
- Category
- Data Flow
- Content
content_type = mimetypes.guess_type(str(path))[0] or "application/octet-stream" with path.open("rb") as fh: put = requests.put( upload_url, data=fh, headers={"Content-Type": content_type},- Confidence
- 77% confidence
- Finding
- put = requests.put( upload_url, data=fh, headers={"Content-Type": content_type}, timeout=300, )
