Tainted flow: 'url' from os.environ.get (line 121, credential/environment) → urllib.request.urlopen (network output)
Critical
- Category
- Data Flow
- Content
def download_url(url: str, destination: Path) -> None: destination.parent.mkdir(parents=True, exist_ok=True) with urllib.request.urlopen(url, timeout=600) as response: destination.write_bytes(response.read())- Confidence
- 85% confidence
- Finding
- with urllib.request.urlopen(url, timeout=600) as response:
