Component: python/vyos/remote.py
Finding (automated security review, MEDIUM): In the CurlC uploader, upload() runs:
print(f'{self.command} "{self.urlstring}"')self.urlstring is the full urllib.parse.urlunsplit(url) and may contain userinfo (scheme://user:password@host/...). Printing it to stdout exposes embedded credentials in op-mode output and any captured logs.
Confirmation it is leftover debug: This is the only such print(self.command/urlstring) in the file. The sibling CurlC.download() performs the equivalent operation without the print, so the line is not needed for functionality.
Proposed fix (see PR): Remove the print(...) line. (If diagnostic output is ever wanted, redact userinfo first via urlsplit → strip netloc before @ → urlunsplit.)
Surfaced by automated security review on the rolling branch. The flagged code is already public in vyos/vyos-1x.