Tainted flow: 'PYTHON_BIN' from os.environ.get (line 17, credential/environment) → subprocess.run (code execution)
Medium
- Category
- Data Flow
- Content
def run_sync(): """Run sync.py and return output.""" result = subprocess.run( [PYTHON_BIN, SYNC_SCRIPT], capture_output=True, text=True, cwd=BASE_DIR, timeout=120, )- Confidence
- 88% confidence
- Finding
- result = subprocess.run( [PYTHON_BIN, SYNC_SCRIPT], capture_output=True, text=True, cwd=BASE_DIR, timeout=120, )
