subprocess module call
- Category
- Dangerous Code Execution
- Confidence
- 89% confidence
- Finding
The supervisor launches a subprocess from a command string that can come from an explicit parameter or the MEMORY_TENCENTDB_GATEWAY_CMD environment variable. Although shell=True is not used, this still allows execution of an attacker-controlled binary or argument set if configuration or environment input is influenced, which is a meaningful command-execution risk in plugin/agent deployments.
- Content
python stdout_target = subprocess.DEVNULL stderr_target = subprocess.DEVNULL self._process = subprocess.Popen( shlex.split(self._gateway_cmd), env=env, stdout=stdout_target,
