Tainted flow: 'req_url' from os.environ.get (line 146, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
req_url = url headers = {"Authorization": f"Bearer {key}", "Content-Type": "application/json"} resp = requests.post( req_url, headers=headers, json={- Confidence
- 98% confidence
- Finding
- resp = requests.post( req_url, headers=headers, json={ "contents": [{"parts": [{"text": prompt}]}], "generationConfig": { "responseM
