subprocess module call
Medium
- Category
- Dangerous Code Execution
- Content
shutil.copy2(image_path, workspace_path) # 发送到飞书 result = subprocess.run([ sys.executable, "-c", f"from message import message; message(action='send', media='{workspace_path}')" ], capture_output=True, text=True)- Confidence
- 95% confidence
- Finding
- result = subprocess.run([ sys.executable, "-c", f"from message import message; message(action='send', media='{workspace_path}')" ], capture_output=True, text=T
