Context-Inappropriate Capability
High
- Confidence
- 98% confidence
- Finding
- The script builds key=value lines from parsed remote HTML and then executes them with eval in format_output. Because the weather page content is untrusted network data, an attacker who can influence the upstream response or parsing output could inject shell metacharacters or command substitutions and achieve arbitrary command execution on the host.
