interpolated-database-query
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
SecuritySecurityquery.py
MEDIUMSecurityMEDIUM
query.py
The code contains a significant SQL injection risk because user_id is directly embedded into a SQL query. Use a parameterized query such as SELECT name FROM users WHERE id = ? (with user_id passed separately), and ensure the Python string is syntactically complete. No evidence of malicious behavior or intentional obfuscation is present.
Confidence: 99%Severity: 82%
Audit Metadata