subprocess module call
Medium
- Category
- Dangerous Code Execution
- Content
"""通过临时文件执行 ab eval(避免 shell 转义)""" js_file = str(TMP_DIR / "_ab_eval_tmp.js") Path(js_file).write_text(js) return subprocess.run( f"agent-browser eval \"$(cat {js_file})\"", shell=True, capture_output=True, text=True, timeout=timeout, )- Confidence
- 97% confidence
- Finding
- return subprocess.run( f"agent-browser eval \"$(cat {js_file})\"", shell=True, capture_output=True, text=True, timeout=timeout, )
