A subprocess launched through a shell can allow command injection. — Asset 1
High · 5 original findings
Source code or credentials may permit unauthorized access or unsafe application behavior.
Target: Asset 1
What to do next: Change the code to remove the reported unsafe pattern.
Related checks (5)
Detected user input entering a `subprocess` call unsafely. This could result in a command injection vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a dictionary to allowlist a set of commands. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.flask.security.injection.subprocess-injection.subprocess-injection is no longer reported.
Official scanner references: https://github.com/semgrep/semgrep · https://semgrep.dev/ · https://semgrep.dev/docs/cheat-sheets/python-command-injection/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID: finding-345393569beccd54f6bea5e46bc227f6
Why this priority
- Source severity: ERROR
- Source confidence: HIGH
Evidence SHA-256
1d2ad2c5a3c9af2fed7095b7c870681073a85ffc7a1bec4efe8876fc517bd2bc
Evidence evidence-24cdce67b4524a9cd895dc86d3288f19 · Check semgrep · Observed 2026-10-07 01:34:58 UTC- Source rule
python.flask.security.injection.subprocess-injection.subprocess-injection- Evidence summary
- [redacted evidence summary]
- Evidence kind
- Source Code
- Engine run ID
ddfbdd4f-3c68-4f42-9af7-2eb64f6fecd4- Artifact ID
66921f2e-b840-4849-8f66-69e62ab8919a- Result pointer
[redacted result pointer]- Evidence location
- [redacted location]
Scanner-provided details
- Scanner-assigned CWE
CWE-78
Related framework references
- OWASP Top 10 2021 / A03:2021 — Injection
Relationship: related
Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
A subprocess launched through a shell can allow command injection. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule ai-security-scanner.python.shell-true is no longer reported.
Official scanner references: https://github.com/semgrep/semgrep · https://semgrep.dev/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID: finding-e30c4507ca0672d1930ead1a1de9bc38
Why this priority
- Source severity: ERROR
- Source confidence: HIGH
Evidence SHA-256
1d2ad2c5a3c9af2fed7095b7c870681073a85ffc7a1bec4efe8876fc517bd2bc
Evidence evidence-4b38a87af90a024109c7a7e05fd8f539 · Check semgrep · Observed 2026-10-07 01:34:58 UTC- Source rule
ai-security-scanner.python.shell-true- Evidence summary
- [redacted evidence summary]
- Evidence kind
- Source Code
- Engine run ID
ddfbdd4f-3c68-4f42-9af7-2eb64f6fecd4- Artifact ID
66921f2e-b840-4849-8f66-69e62ab8919a- Result pointer
[redacted result pointer]- Evidence location
- [redacted location]
Scanner-provided details
- Scanner-assigned CWE
CWE-78
Related framework references
- ISO/IEC 27001 2022 / A.8.28 — Secure coding practices
Relationship: related
Why related: Static-analysis evidence that Python code invokes an operating-system shell is related to secure development and pre-execution dangerous-construct checks. AIDEFEND's AI-generated-artifact coordinate applies when the selected code was generated or materially changed by AI. - ISO/IEC 27001 2022 / A.8.29 — Security testing before acceptance
Relationship: related
Why related: Static-analysis evidence that Python code invokes an operating-system shell is related to secure development and pre-execution dangerous-construct checks. AIDEFEND's AI-generated-artifact coordinate applies when the selected code was generated or materially changed by AI. - NIST CSF 2.0 / PR.PS-06 — Secure software development practices
Relationship: related
Why related: Static-analysis evidence that Python code invokes an operating-system shell is related to secure development and pre-execution dangerous-construct checks. AIDEFEND's AI-generated-artifact coordinate applies when the selected code was generated or materially changed by AI. - OWASP Top 10 2021 / A03:2021 — Injection
Relationship: related
Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Detected subprocess function 'run' with user controlled data. A malicious actor could leverage this to perform command injection. You may consider using 'shlex.escape()'. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use is no longer reported.
Official scanner references: https://docs.python.org/3/library/shlex.html · https://docs.python.org/3/library/subprocess.html · https://github.com/semgrep/semgrep · https://semgrep.dev/ · https://semgrep.dev/docs/cheat-sheets/python-command-injection/ · https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID: finding-2ead0ffc8cedc2e7de0c930af559f9d9
Why this priority
- Source severity: ERROR
- Source confidence: MEDIUM
Evidence SHA-256
1d2ad2c5a3c9af2fed7095b7c870681073a85ffc7a1bec4efe8876fc517bd2bc
Evidence evidence-9a3324107b79f11dd3ba264736b436f2 · Check semgrep · Observed 2026-10-07 01:34:58 UTC- Source rule
python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use- Evidence summary
- [redacted evidence summary]
- Evidence kind
- Source Code
- Engine run ID
ddfbdd4f-3c68-4f42-9af7-2eb64f6fecd4- Artifact ID
66921f2e-b840-4849-8f66-69e62ab8919a- Result pointer
[redacted result pointer]- Evidence location
- [redacted location]
Scanner-provided details
- Scanner-assigned CWE
CWE-78
Related framework references
- OWASP Top 10 2021 / A03:2021 — Injection
Relationship: related
Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
Scanner-provided remediation: [redacted scanner-provided remediation]
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.lang.security.audit.subprocess-shell-true.subprocess-shell-true is no longer reported.
Official scanner references: https://docs.python.org/3/library/subprocess.html · https://github.com/semgrep/semgrep · https://semgrep.dev/ · https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID: finding-a416946d7e152b3c0cf170b0b01c1b0c
Why this priority
- Source severity: ERROR
- Source confidence: MEDIUM
Evidence SHA-256
1d2ad2c5a3c9af2fed7095b7c870681073a85ffc7a1bec4efe8876fc517bd2bc
Evidence evidence-5e1d497424eb308a420a759334568b06 · Check semgrep · Observed 2026-10-07 01:34:58 UTC- Source rule
python.lang.security.audit.subprocess-shell-true.subprocess-shell-true- Evidence summary
- [redacted evidence summary]
- Evidence kind
- Source Code
- Engine run ID
ddfbdd4f-3c68-4f42-9af7-2eb64f6fecd4- Artifact ID
66921f2e-b840-4849-8f66-69e62ab8919a- Result pointer
[redacted result pointer]- Evidence location
- [redacted location]
Scanner-provided details
- Scanner-provided remediation
- [redacted scanner-provided remediation]
- Scanner-assigned CWE
CWE-78
Related framework references
- OWASP Top 10 2021 / A03:2021 — Injection
Relationship: related
Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Detected subprocess function 'run' without a static string. If this data can be controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it is not controllable by an external resource. You may consider using 'shlex.escape()'. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.lang.security.audit.dangerous-subprocess-use-audit.dangerous-subprocess-use-audit is no longer reported.
Official scanner references: https://docs.python.org/3/library/shlex.html · https://docs.python.org/3/library/subprocess.html · https://github.com/semgrep/semgrep · https://semgrep.dev/ · https://semgrep.dev/docs/cheat-sheets/python-command-injection/ · https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID: finding-057f327431190b7c09d49efeb94c2459
Why this priority
- Source severity: ERROR
- Source confidence: LOW
Evidence SHA-256
1d2ad2c5a3c9af2fed7095b7c870681073a85ffc7a1bec4efe8876fc517bd2bc
Evidence evidence-2509d415b86e780bb1b094d4cc2320a9 · Check semgrep · Observed 2026-10-07 01:34:58 UTC- Source rule
python.lang.security.audit.dangerous-subprocess-use-audit.dangerous-subprocess-use-audit- Evidence summary
- [redacted evidence summary]
- Evidence kind
- Source Code
- Engine run ID
ddfbdd4f-3c68-4f42-9af7-2eb64f6fecd4- Artifact ID
66921f2e-b840-4849-8f66-69e62ab8919a- Result pointer
[redacted result pointer]- Evidence location
- [redacted location]
Scanner-provided details
- Scanner-assigned CWE
CWE-78
Related framework references
- OWASP Top 10 2021 / A03:2021 — Injection
Relationship: related
Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.