#701 SEC-05: Shell command injection mitigation incomplete

closed high Created 2025-12-25 02:56 · Updated 2025-12-25 03:32

Description

Edit
Location: shell_command.py:60-83. Issue: While shlex.quote() used for variables, base command passed to shell=True. Unsanitized user input in command template allows injection. Fix: Validate command templates during submission, consider disallowing shell=True.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...