Tainted flow: 'host' from os.environ.get (line 5, credential/environment) β requests.post (network output)
Critical
- Category
- Data Flow
- Content
token = os.environ.get("TUNNEL_AGENT_TOKEN") # 1. θ·εδΈ΄ζΆη«―ε£ resp = requests.post(f"http://{host}:{http_port}/api/session", json={"token": token}) port = resp.json()["port"] # 2. η«ε³θΏζ₯- Confidence
- 97% confidence
- Finding
- resp = requests.post(f"http://{host}:{http_port}/api/session", json={"token": token})
