Context-Inappropriate Capability
Low
- Confidence
- 86% confidence
- Finding
- Allowing executable and workspace paths to be overridden by environment variables can redirect the application to attacker-controlled Python files if the deployment environment is compromised or misconfigured. Because these paths are later executed, this becomes a code-execution primitive rather than simple configuration flexibility.
