vulns.co
/
GKData.io MCP

Python Software Foundation · 1 min read

Python subprocess: executable, argument, and interpreter boundaries

Runtime documentation distinguishes the selected executable, its arguments, and shell interpretation. Python does not implicitly select a shell, but Windows may launch batch files through one. The companion shlex reference limits its quoting guarantees to Unix shells; quoting is not a portable substitute for understanding the receiving interpreter.

Open the reference Implementation GuideReviewed 2026-10-03

How to use this reference

Editorial learning objective: distinguish preserving argument boundaries from authorizing their meaning. Review which executable and interpreter receive data, what actions the receiving program assigns to arguments, and whether those actions fit the intended authority. This resource supports conceptual design review, without execution recipes.

Before reading

  • Basic familiarity with processes, arguments, and operating-system differences.

Context and limits

  • Windows batch-file handling can involve shell parsing even when the application has not explicitly selected a shell. The runtime guidance for this case is conditional, not a universal recommendation to enable shell execution.
  • shlex quoting is not guaranteed correct for non-POSIX shells or Windows shells.
  • The authorization distinction is editorial synthesis, not a claim that these Python APIs enforce application policy.
  • No vulnerability finding, award, payload, reproduction sequence, or testing authorization is established.

Sources and provenance

  1. subprocess: Security Considerations Python Software Foundation · reviewed 2026-10-03
  2. shlex.quote: Unix-shell portability warning Python Software Foundation · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software