os.system() or os exec-family call
High
- Category
- Dangerous Code Execution
- Content
elif command == "mcp": # 启动 MCP 服务器 os.system(f"python {Path(__file__).parent}/mcp_server.py {' '.join(sys.argv[2:])}") elif command == "test": # 运行测试- Confidence
- 99% confidence
- Finding
- os.system(f"python {Path(__file__).parent}/mcp_server.py {' '.join(sys.argv[2:])}")
