Tainted flow: 'req' from os.environ.get (line 43, credential/environment) → urllib.request.urlopen (network output)
Critical
- Category
- Data Flow
- Content
print(f" Downloading from: {asset_url}") req = urllib.request.Request(asset_url) with urllib.request.urlopen(req, timeout=60) as r: with open(output_path, "wb") as f: f.write(r.read()) print(f" Saved to: {output_path}")- Confidence
- 91% confidence
- Finding
- with urllib.request.urlopen(req, timeout=60) as r:
