Medium severityPythonSensitive Data ExposureMEDIUM confidence
Sensitive Data In URL Query
A secret or PII value is placed into a URL/query string (CWE-598).
Standards mapping
- OWASP Top 10
- A02:2021 - Cryptographic Failures
- OWASP ASVS
- V8.3.1 (L2)V8.3.4 (L2)
Vulnerable vs. safe
Flagged by this check
requests.get("https://api.example.com/verify?token=" + token)Passes - the safe pattern
requests.post("https://api.example.com/verify", data={"token": token})Why it matters & how to fix it
A secret or PII value is placed into a URL/query string (CWE-598). URLs are logged by servers, proxies, and browser history, leaking the value. Send sensitive data in the request body over TLS (POST), never in the query string.
References
Rule ID integsec-python-sensitive-data-in-url-query - engine: Opengrep - license: MIT - Copyright (c) IntegSec Inc.
TurboPentest runs this check automatically
Connect a GitHub repo and this check runs on every white-box pentest - AI-validated and reported with proof, from $99 per target.
Start a pentestRelated checks
- JavaScript / TypeScript - Sensitive Data ExposureError Stack In Response
- JavaScript / TypeScript - Sensitive Data ExposurePII PHI In Logs
- JavaScript / TypeScript - Sensitive Data ExposureSecret In Logs
- JavaScript / TypeScript - Sensitive Data ExposureSensitive Data Client Storage
- JavaScript / TypeScript - Sensitive Data ExposureSensitive Data In URL Query
- Python - Sensitive Data ExposureFlask Traceback In Response