subprocess module call
Medium
- Category
- Dangerous Code Execution
- Content
if not app_key: # 从环境变量读 app_key = subprocess.run( ["bash", "-c", "echo $XG_BIZ_API_KEY"], capture_output=True, text=True ).stdout.strip()- Confidence
- 87% confidence
- Finding
- app_key = subprocess.run( ["bash", "-c", "echo $XG_BIZ_API_KEY"], capture_output=True, text=True ).stdout.strip()
