byted-seedream-image-generate
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
SecuritySecurityscripts/seedream_image_generate.py
MEDIUMSecurityMEDIUM
scripts/seedream_image_generate.py
This module appears to be a legitimate API client for image generation, not an obvious malware/backdoor implementation. However, it has a serious security weakness: it logs the full Authorization header (Bearer API key) and detailed request payloads to stdout, which can leak credentials and user data into CI logs, terminals, or monitoring systems. Additionally, API_BASE is environment-controlled without allowlist/validation, so a poisoned environment could redirect the bearer token and prompts to an unintended endpoint. Remediate by removing/redacting secret logging, using a configurable debug logger, and validating/allowlisting API destinations.
Confidence: 73%Severity: 78%
Audit Metadata