Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 90% confidence
- Finding
This duplicate finding refers to the same Windows shell-backed process launch. While the current inputs are static, the pattern is still unsafe by design because shell interpretation is unnecessary and increases the risk of command or parameter abuse.
- Content
python system = platform.system() if system == "Windows": subprocess.Popen(["start", "brave", url], shell=True) elif system == "Darwin": subprocess.Popen(["open", "-a", "Brave Browser", url]) else:
