Tainted flow: 'request' from os.environ.get (line 67, credential/environment) → urllib.request.urlopen (network output)
Critical
- Category
- Data Flow
- Content
method="POST", ) try: with urllib.request.urlopen(request, timeout=60) as response: result = parse_payload(response.read(), response.headers.get("content-type", "")) return result, response.headers.get("mcp-session-id") or session_id except urllib.error.HTTPError as error:- Confidence
- 84% confidence
- Finding
- The script allows AI_HIVE_MCP_URL to override the default MCP endpoint, then sends authentication headers derived from AI_HIVE_API_KEY or AI_HIVE_ACCESS_TOKEN to that URL. If an attacker can influence the environment, credentials may be exfiltrated to an arbitrary server and tool calls could be redirected to an untrusted endpoint.
