Tainted flow: 'token_url' from os.environ.get (line 40, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
# 获取 access_token token_url = f"https://aip.baidubce.com/oauth/2.0/token?grant_type=client_credentials&client_id={api_key}&client_secret={secret_key}" token = requests.post(token_url).json().get("access_token") # 调用发票识别 with open(image_path, "rb") as f:- Confidence
- 79% confidence
- Finding
- token = requests.post(token_url).json().get("access_token")
