Tainted flow: 'XENODIA_BASE_URL' from os.environ.get (line 53, credential/environment) → requests.post (network output)
Critical
- Category
- Data Flow
- Content
signature = await _sign_message(cdp, account, message) try: resp = requests.post( f"{XENODIA_BASE_URL}/v1/auth/verify", json={"challenge_id": challenge_id, "signature": signature}, timeout=10 )- Confidence
- 88% confidence
- Finding
- resp = requests.post( f"{XENODIA_BASE_URL}/v1/auth/verify", json={"challenge_id": challenge_id, "signature": signature}, timeout=10 )
