High severityPythonHardcoded SecretsMEDIUM confidence
Hardcoded Credential Literal
A credential or API key is hardcoded as a string literal (CWE-798).
Standards mapping
- OWASP ASVS
- V6.4.1 (L2)V2.10.4 (L2)
Vulnerable vs. safe
Flagged by this check
password = "S3cr3tP@ssw0rd!"Passes - the safe pattern
password = os.environ["APP_PASSWORD"]Why it matters & how to fix it
A credential or API key is hardcoded as a string literal (CWE-798). Hardcoded secrets leak through version control, logs, and binaries. Load the value from an environment variable or secrets manager (os.environ, AWS Secrets Manager, Vault) and rotate anything already committed.
References
Rule ID integsec-python-hardcoded-credential-literal - engine: Opengrep - license: MIT - Copyright (c) IntegSec Inc.
TurboPentest runs this check automatically
Connect a GitHub repo and this check runs on every white-box pentest - AI-validated and reported with proof, from $99 per target.
Start a pentestRelated checks
- JavaScript / TypeScript - Hardcoded SecretsBasic Auth Credentials In URL
- JavaScript / TypeScript - Hardcoded SecretsDB Connection String With Credentials
- JavaScript / TypeScript - Hardcoded SecretsHardcoded Credential String
- JavaScript / TypeScript - Hardcoded SecretsHardcoded Crypto Key Or IV
- Python - Hardcoded SecretsBasic Auth Credentials In URL
- Python - Hardcoded SecretsDB Connection String Credentials