Tainted flow: 'url' from os.environ.get (line 180, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
data = {"model": "whisper-1", "language": language} headers = {"Authorization": f"Bearer {API_KEY}"} if API_KEY else {} response = requests.post(url, files=files, data=data, headers=headers) if response.status_code != 200: raise Exception(f"转写失败: {response.status_code} - {response.text}")- Confidence
- 94% confidence
- Finding
- response = requests.post(url, files=files, data=data, headers=headers)
