Tainted flow: 'cmd' from os.getenv (line 113, credential/environment) → subprocess.run (code execution)
Medium
- Category
- Data Flow
- Content
cmd.extend(["--language", language]) logger.info(f"Running: {' '.join(cmd)}") subprocess.run(cmd, check=True, capture_output=True) # Read result txt_path = Path(f"{output_base}.txt")- Confidence
- 84% confidence
- Finding
- subprocess.run(cmd, check=True, capture_output=True)
