Tainted flow: 'filepath' from os.environ.get (line 45, credential/environment) → open (file write)
Medium
- Category
- Data Flow
- Content
else: new_content = content with open(filepath, 'w', encoding='utf-8') as f: f.write(new_content) print(f"[OK] Saved to workspace: {filepath}")- Confidence
- 91% confidence
- Finding
- with open(filepath, 'w', encoding='utf-8') as f:
