Tainted flow: 'request' from os.environ.get (line 67, credential/environment) → urllib.request.urlopen (network output)
Critical
- Category
- Data Flow
- Content
method="POST", ) try: with urllib.request.urlopen(request, timeout=60) as response: result = parse_payload(response.read(), response.headers.get("content-type", "")) return result, response.headers.get("mcp-session-id") or session_id except urllib.error.HTTPError as error:- Confidence
- 94% confidence
- Finding
- The script sends credentials from environment variables to a remote endpoint whose base URL is taken from AI_HIVE_MCP_URL without any allowlist or origin validation. If an attacker can influence that environment variable, they can redirect requests and exfiltrate the API key or bearer token to an arbitrary server.
