Tainted flow: 'TOKEN_FILE' from os.environ.get (line 26, credential/environment) → open (file write)
Medium
- Category
- Data Flow
- Content
def save_master_token(token): ensure_config_dir() with open(TOKEN_FILE, "w") as f: f.write(token) os.chmod(TOKEN_FILE, 0o600)- Confidence
- 79% confidence
- Finding
- with open(TOKEN_FILE, "w") as f:
