Tainted flow: 'BASE_URL' from os.getenv (line 8, credential/environment) → requests.get (network output)
Critical
- Category
- Data Flow
- Content
if end_date: params["end_date"] = end_date resp = requests.get(f"{BASE_URL}/articles", headers=HEADERS, params=params, timeout=30) resp.raise_for_status() return resp.json()- Confidence
- 92% confidence
- Finding
- resp = requests.get(f"{BASE_URL}/articles", headers=HEADERS, params=params, timeout=30)
