Python

Shell Injection in Python

PythonStandard Library (Subprocess)Running Commandsintermediate

What this snippet does

Using shell=True with string interpolation exposes the system to shell injection attacks; always use lists.

Expected output

Always use list arguments

Why practise typing this

Typing standard library (subprocess) code builds muscle memory for the symbols and indentation Python uses most, which prose-based typing tests never cover. DevType measures your words per minute and accuracy on this snippet and tracks the individual characters you mistype, so later lessons can target them.

More Python practice

Browse all Python snippets →