video
Audited by Socket on Sep 17, 2026
3 alerts found:
Anomalyx2SecurityThe fragment implements a video API client and does not show clear malware, persistence, data theft, or command execution. It has meaningful security weaknesses: TLS verification is disabled, traffic is routed through a plain HTTP internal proxy, a hardcoded placeholder authorization value is used, and remote URLs are followed without allowlisting or response-size validation. The unknown _cost_track helper and proxy configuration require separate review, especially because they may receive request payloads and API responses.
The code appears to implement a legitimate local/media publishing utility and contains no evident malware, credential theft, or backdoor. It has significant security risks if exposed to untrusted callers: unsanitized rename values can enable path traversal or arbitrary destination writes, and unrestricted HTTP(S) fetching can enable SSRF. The URL download also permits memory exhaustion and redirects, while extension-only validation allows mislabeled content.
The code appears to be a video-generation polling and download utility rather than overt malware. It has meaningful security weaknesses: disabled TLS verification, hardcoded credential-like authorization, an unvalidated remotely supplied download URL, and unsanitized request_id use in a filesystem path. These issues warrant remediation and review of _cost_track, but the fragment contains no clear data theft, destructive behavior, or backdoor. The hardcoded key appears deliberately fake, though its presence remains unsafe practice.