Problem
A fixed argument-vector call with shell=False, an input-concatenated shell command and an unknown caller receive the same generic subprocess finding. The generic explanation suggests injection, and its remediation recommends shell=False even when that mode is already used.
The fixed-argv detector probe emitted MEDIUM AST4 for this scanner input:
import subprocess
subprocess.run(["ls", "-la"], shell=False)
The code does launch a process, but the finding does not show an injection path and recommends a change already present in the code.
Expected behavior
Describe the execution mode and any unknown input accurately. Distinguish fixed argv from untrusted shell strings while still detecting dangerous executables invoked with literal arguments.
Correct the explanation and remediation under the existing scoring policy, and keep genuine process-execution risks visible.
Related: #326 discusses source-surface information; #644 includes a separate code-loading risk. This issue covers the AST4 explanation and remediation.
Relevant code
behavioral_ast.py:565, pattern_defaults.py:119, pattern_defaults.py:401.
Problem
A fixed argument-vector call with
shell=False, an input-concatenated shell command and an unknown caller receive the same generic subprocess finding. The generic explanation suggests injection, and its remediation recommendsshell=Falseeven when that mode is already used.The fixed-argv detector probe emitted MEDIUM AST4 for this scanner input:
The code does launch a process, but the finding does not show an injection path and recommends a change already present in the code.
Expected behavior
Describe the execution mode and any unknown input accurately. Distinguish fixed argv from untrusted shell strings while still detecting dangerous executables invoked with literal arguments.
Correct the explanation and remediation under the existing scoring policy, and keep genuine process-execution risks visible.
Related: #326 discusses source-surface information; #644 includes a separate code-loading risk. This issue covers the AST4 explanation and remediation.
Relevant code
behavioral_ast.py:565, pattern_defaults.py:119, pattern_defaults.py:401.