os.system() or os exec-family call
- Category
- Dangerous Code Execution
- Confidence
- 95% confidence
- Finding
The installer executes shell commands via os.system(), which is inherently risky because it delegates parsing to the shell and can turn unexpected whitespace, metacharacters, or future variable changes into command execution issues. In this file the current command strings are mostly constant, so this is not an obvious injection sink today, but it still grants broad system-modification capability in an installer that runs as root and expands the attack surface unnecessarily.
- Content
python LOGROTATE_CONF = "/etc/logrotate.d/stock-monitor" def run(cmd): r = os.system(cmd) if r != 0: print(f"❌ 命令失败: {cmd}") sys.exit(r)
