rules:
- id: dangerous-testcapi-run-in-subinterp
  patterns:
  - pattern-either:
    - pattern: |
        _testcapi.run_in_subinterp($PAYLOAD, ...)
    - pattern: |
        test.support.run_in_subinterp($PAYLOAD, ...)
  - pattern-not: |
      _testcapi.run_in_subinterp("...", ...)
  - pattern-not: |
      test.support.run_in_subinterp("...", ...)
  message: >-
    Found dynamic content in `run_in_subinterp`.
    This is dangerous if external data can reach this function call because it allows
    a malicious actor to run arbitrary Python code.
    Ensure no external data reaches here.
  metadata:
    cwe: "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')"
    owasp: 'A1: Injection'
    category: security
    technology:
    - python
  severity: WARNING
  languages:
  - python
