Tainted flow: 'COORDINATOR_URL' from os.environ.get (line 25, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
def get_work(wallet): """Request a work unit from coordinator""" try: res = requests.post( f"{COORDINATOR_URL}/api/work", json={'wallet': wallet, 'api_key': API_KEY}, timeout=30- Confidence
- 96% confidence
- Finding
- res = requests.post( f"{COORDINATOR_URL}/api/work", json={'wallet': wallet, 'api_key': API_KEY}, timeout=30 )
