We are sunsetting Hakiri on January 31 2022. To learn more please refer to this document.

Discovered almost 5 years ago
Source: static code analysis
Category: Command Injection
Confidence level: Medium


Possible command injection



`#{instructions.join(" ")} &> /dev/null`

Category description: Command injection occurs when shell commands unsafely include user-manipulatable values.

Solution: fix the issue in app/models/optimized_image.rb or mark it as false positive.