Tainted flow: 'files' from requests.get (line 568, network input) → requests.post (network output)
Medium
- Category
- Data Flow
- Content
img.raise_for_status() content_type = img.headers.get("Content-Type", "image/jpeg") files = {"media": ("thumb.jpg", img.content, content_type)} resp = requests.post( MATERIAL_ADD_URL, params={"access_token": token, "type": "image"}, files=files,- Confidence
- 87% confidence
- Finding
- resp = requests.post( MATERIAL_ADD_URL, params={"access_token": token, "type": "image"}, files=files, timeout=self.timeout, )
