Tainted flow: 'cmd' from os.environ.get (line 30, credential/environment) → subprocess.run (code execution)
Medium
- Category
- Data Flow
- Content
"-d", json.dumps(payload) ] result = subprocess.run(cmd, capture_output=True, text=True, timeout=35) data = json.loads(result.stdout) if data.get("base_resp", {}).get("status_code") == 0:- Confidence
- 84% confidence
- Finding
- result = subprocess.run(cmd, capture_output=True, text=True, timeout=35)
