Tainted flow: 'LICENSE_SERVER' from os.getenv (line 16, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
if not PRO_LICENSE_KEY: return False try: resp = requests.post( f"{LICENSE_SERVER}/api/validate", json={"key": PRO_LICENSE_KEY, "product": "polymarket-sniper-pro"}, timeout=5- Confidence
- 95% confidence
- Finding
- resp = requests.post( f"{LICENSE_SERVER}/api/validate", json={"key": PRO_LICENSE_KEY, "product": "polymarket-sniper-pro"}, timeout=5 )
