Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The script requests a routine access token and appends it directly to the returned URL, then prints that URL to stdout. Query-string tokens are easily exposed through shell history, CI/CD logs, terminal scrollback, screenshots, referrer leakage, and shared logs, which can grant unintended access to the deployed routine for the token lifetime.
