subprocess module call
Medium
- Category
- Dangerous Code Execution
- Content
conda_activate_cmd = f'call {DEFAULT_CONDA_PATH} activate {DEFAULT_ENV}' full_cmd = f"{conda_activate_cmd} && {' '.join(command)}" proc = subprocess.run( ["cmd.exe", "/c", full_cmd], capture_output=True, text=True,- Confidence
- 95% confidence
- Finding
- proc = subprocess.run( ["cmd.exe", "/c", full_cmd], capture_output=True, text=True, cwd=cwd, env=os.environ.copy() )
