Tainted flow: 'adb_server' from os.environ.get (line 15, credential/environment) → subprocess.run (code execution)
Medium
- Category
- Data Flow
- Content
if adb_server: # If it looks like an IP address/port, attempt to connect first if ":" in adb_server: subprocess.run(["adb", "connect", adb_server], capture_output=True) base_cmd.extend(["-s", adb_server]) cmd = base_cmd + args- Confidence
- 86% confidence
- Finding
- subprocess.run(["adb", "connect", adb_server], capture_output=True)
