From ef94b134c3abe53bb330ddb00e5631eaa031cdea Mon Sep 17 00:00:00 2001 From: Andi Radulescu Date: Thu, 14 May 2026 05:36:47 +0300 Subject: [PATCH] common: avoid shell in sudo_read (#38022) --- common/utils.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/common/utils.py b/common/utils.py index 28b9274d82..183363f39d 100644 --- a/common/utils.py +++ b/common/utils.py @@ -48,7 +48,7 @@ def sudo_write(val: str, path: str) -> None: def sudo_read(path: str) -> str: try: - return subprocess.check_output(f"sudo cat {path}", shell=True, encoding='utf8').strip() + return subprocess.check_output(["sudo", "cat", "--", path], encoding='utf8').strip() except Exception: return ""