Tainted flow: 'request' from os.environ.get (line 67, credential/environment) → urllib.request.urlopen (network output)
Critical
- Category
- Data Flow
- Content
method="POST", ) try: with urllib.request.urlopen(request, timeout=60) as response: result = parse_payload(response.read(), response.headers.get("content-type", "")) return result, response.headers.get("mcp-session-id") or session_id except urllib.error.HTTPError as error:- Confidence
- 96% confidence
- Finding
- `post()` sends authentication headers built from `AI_HIVE_API_KEY` or `AI_HIVE_ACCESS_TOKEN` to `MCP_URL`, which is overrideable via the `AI_HIVE_MCP_URL` environment variable. If an attacker can influence that environment variable or execution environment, they can redirect requests to an arbitrary server and capture the API key or bearer token, causing credential exfiltration and unauthorized API use.
