subprocess module call
Medium
- Category
- Dangerous Code Execution
- Content
# Best-effort: ensure sudo timestamp for this user is not reused implicitly. subprocess.run([sudo_bin, "-k"], check=False, capture_output=True, text=True) append_audit({"action": "exec_start", "argv": argv, "use_sudo": use_sudo}) result = subprocess.run(exec_argv) append_audit({"action": "exec_finish", "argv": argv, "use_sudo": use_sudo, "returncode": result.returncode}) return result.returncode- Confidence
- 91% confidence
- Finding
- result = subprocess.run(exec_argv)
