Tainted flow: 'cmd' from os.environ.get (line 263, credential/environment) → subprocess.run (code execution)
Medium
- Category
- Data Flow
- Content
"--filename", str(output_path), "--resolution", resolution, ] result = subprocess.run(cmd, capture_output=True, text=True) if result.returncode != 0: print(f" [ERR] failed: {result.stderr.strip().splitlines()[-1] if result.stderr else 'unknown error'}")- Confidence
- 95% confidence
- Finding
- result = subprocess.run(cmd, capture_output=True, text=True)
