subprocess module call
- Category
- Dangerous Code Execution
- Confidence
- 98% confidence
- Finding
The exec.run path executes attacker-controlled input via
sh -corcmd /C, which enables arbitrary shell command execution. The blacklist-based_is_dangerousfilter is incomplete and easily bypassed with alternate syntax, encoding, indirection, separators, or benign-looking commands that still exfiltrate data or modify the system.- Content
python shell = "cmd" if os.name == "nt" else "sh" flag = "/C" if os.name == "nt" else "-c" try: cp = subprocess.run( [shell, flag, cmd], capture_output=True, timeout=timeout, )
