Tainted flow: 'req' from os.environ.get (line 826, credential/environment) → urllib.request.urlopen (network output)
Critical
- Category
- Data Flow
- Content
req.add_header("Authorization", f"Bearer {api_key}") req.add_header("Content-Type", f"multipart/form-data; boundary={boundary}") try: resp = urllib.request.urlopen(req, timeout=timeout) except urllib.error.HTTPError as e: detail = e.read().decode("utf-8", errors="replace")[:400] raise CueAPIError(e.code, detail, "/file_server/upload") from e- Confidence
- 82% confidence
- Finding
- resp = urllib.request.urlopen(req, timeout=timeout)
