Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 94% confidence
- Finding
This duplicate finding identifies the same underlying weakness: launching via shell=True unnecessarily exposes the call to shell semantics and executable resolution issues. Even with a fixed URL, this is a genuine unsafe pattern because an attacker controlling the environment or a later code change introducing variable input could abuse the launch behavior.
- Content
python system = platform.system() if system == "Windows": subprocess.Popen(["start", "brave", url], shell=True) elif system == "Darwin": subprocess.Popen(["open", "-a", "Brave Browser", url]) else:
