subprocess module call
Medium
- Category
- Dangerous Code Execution
- Content
return {"success": False, "error": f"只允许结束白名单进程: {', '.join(ALLOWED_PROCESSES)}"} ps = f'Stop-Process -Name "{name_or_pid}" -Force -ErrorAction Stop' subprocess.run(["powershell", "-ExecutionPolicy", "Bypass", "-NoProfile", "-Command", ps], check=True, timeout=10) return {"success": True} except subprocess.CalledProcessError as e: return {"success": False, "error": f"结束进程失败: {e}"}- Confidence
- 82% confidence
- Finding
- subprocess.run(["powershell", "-ExecutionPolicy", "Bypass", "-NoProfile", "-Command", ps], check=True, timeout=10)
