Tainted flow: 'output_path' from os.environ.get (line 279, credential/environment) → open (file write)
Medium
- Category
- Data Flow
- Content
output_path = OUTPUT_DIR / f"mistakes_{timestamp}{ext}" output_path.parent.mkdir(parents=True, exist_ok=True) with open(output_path, 'w', encoding='utf-8') as f: f.write(content) return f"✅ 已导出到: {output_path}"- Confidence
- 94% confidence
- Finding
- with open(output_path, 'w', encoding='utf-8') as f:
