Tainted flow: 'PENDING_FILE' from os.environ.get (line 61, credential/environment) → pathlib.Path.write_text (file write)
Medium
- Category
- Data Flow
- Content
def save_pending(data): """Save pending requests to file""" PENDING_FILE.parent.mkdir(parents=True, exist_ok=True) PENDING_FILE.write_text(json.dumps(data, indent=2)) def submit(model_id: str, input_data: dict, skip_validation: bool = False) -> dict: """Submit a request to the queue with validation"""- Confidence
- 90% confidence
- Finding
- PENDING_FILE.write_text(json.dumps(data, indent=2))
