Tainted flow: 'cmd' from os.environ.get (line 244, credential/environment) → subprocess.run (code execution)
Medium
- Category
- Data Flow
- Content
cmd = [sys.executable, str(script)] try: result = subprocess.run(cmd, capture_output=True, text=True, timeout=120, env=env) if result.returncode == 0: print("✅ Polymarket analyst completed") return parse_polymarket_output(result.stdout)- Confidence
- 78% confidence
- Finding
- result = subprocess.run(cmd, capture_output=True, text=True, timeout=120, env=env)
