subprocess module call
Medium
- Category
- Dangerous Code Execution
- Content
def _run_tool(script: str, args: str): cmd = f"{sys.executable} {TOOLS_DIR}/{script} {args}" try: r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=30) if r.returncode == 0 and r.stdout.strip(): return json.loads(r.stdout) except Exception:- Confidence
- 99% confidence
- Finding
- r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=30)
