Tainted flow: 'cmd' from os.getenv (line 32, credential/environment) → subprocess.run (code execution)
Medium
- Category
- Data Flow
- Content
"-i", RTSP_URL, "-frames:v", "1", "-f", "image2", "-" ] result = subprocess.run(cmd, capture_output=True) return result.stdout def capture_audio(duration=3):- Confidence
- 88% confidence
- Finding
- result = subprocess.run(cmd, capture_output=True)
