ecommerce-mercado-market-intelligence
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalyscripts/damai_mercado_market_intelligence.py
LOWAnomalyLOW
scripts/damai_mercado_market_intelligence.py
The code is primarily an API client with caching and workspace persistence. It contains no clear malware or obfuscated payload. The main security issue is unsanitized SESSION_ID path construction, which can redirect metadata and response writes outside the intended workspace under attacker-controlled environment conditions. A secondary risk is that NEXSCOPE_PROXY_BASE can redirect authenticated requests and expose the API key if misconfigured or attacker-controlled. The fragment is also syntactically incomplete as provided.
Confidence: 97%Severity: 55%
Audit Metadata