Tainted flow: 'INDEX_FILE' from os.getenv (line 17, credential/environment) → open (file write)
Medium
- Category
- Data Flow
- Content
def save_index(index): INDEX_FILE.parent.mkdir(parents=True, exist_ok=True) with open(INDEX_FILE, 'w', encoding='utf-8') as f: json.dump(index, f, ensure_ascii=False, indent=2) def search(query):- Confidence
- 94% confidence
- Finding
- with open(INDEX_FILE, 'w', encoding='utf-8') as f:
