Tainted flow: 'cmd' from os.environ.get (line 125, credential/environment) → subprocess.run (code execution)
Medium
- Category
- Data Flow
- Content
"--default-background-color=00000000", url ] try: subprocess.run(cmd, capture_output=True, timeout=timeout) except subprocess.TimeoutExpired: continue if os.path.exists(png_path) and os.path.getsize(png_path) > 0:- Confidence
- 91% confidence
- Finding
- subprocess.run(cmd, capture_output=True, timeout=timeout)
