subprocess module call
Medium
- Category
- Dangerous Code Execution
- Content
from message_tool import message # 动态导入(避免循环依赖) import subprocess result = subprocess.run( ['python3', '-c', f'from tools import message; message(action="send", channel="feishu", target="user:ou_fd61d5ebc9af22913aa4c21c8e3cac14", message="{alert_msg}")'], capture_output=True, text=True, timeout=15,- Confidence
- 95% confidence
- Finding
- result = subprocess.run( ['python3', '-c', f'from tools import message; message(action="send", channel="feishu", target="user:ou_fd61d5ebc9af22913aa4c21c8e3cac14", mes
