Skip to content

AST4 recommends shell=False when the code already uses it #670

Description

@Spectorian

Problem

A fixed argument-vector call with shell=False, an input-concatenated shell command and an unknown caller receive the same generic subprocess finding. The generic explanation suggests injection, and its remediation recommends shell=False even when that mode is already used.

The fixed-argv detector probe emitted MEDIUM AST4 for this scanner input:

import subprocess
subprocess.run(["ls", "-la"], shell=False)

The code does launch a process, but the finding does not show an injection path and recommends a change already present in the code.

Expected behavior

Describe the execution mode and any unknown input accurately. Distinguish fixed argv from untrusted shell strings while still detecting dangerous executables invoked with literal arguments.

Correct the explanation and remediation under the existing scoring policy, and keep genuine process-execution risks visible.

Related: #326 discusses source-surface information; #644 includes a separate code-loading risk. This issue covers the AST4 explanation and remediation.

Relevant code

behavioral_ast.py:565, pattern_defaults.py:119, pattern_defaults.py:401.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions