Tainted flow: 'webhook_url' from os.getenv (line 200, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
'embeds': [embed] } response = requests.post(webhook_url, json=payload, timeout=10) if response.status_code == 204: logger.info("✅ Discord通知已发送") else:- Confidence
- 91% confidence
- Finding
- response = requests.post(webhook_url, json=payload, timeout=10)
