mobolic/facebook-sdk

Insecure Usage of temp file/directory in Facebook Marketing API libraries

STANAPI opened this issue · 1 comments

Hello, fellow developers! There seems to be an insecure part of the Instagram API libraries, as it's using temp file/directory.

The codes look like this below:

docs_utils.py
DocsDataStore.set('filename', '/tmp/python_sdk_docs.nlsv')

What is the potential risk of this? Is there any way to improve?
image

@STANAPI, since you seem to be creating multiple automated issues that do not apply to this library, you have been blocked from creating new issues or commenting here or on any other Mobolic repository.