My mistake, not knowing python's variable interpoltion well, I thought that the $0 was expanded by it, not the shell. Which, if it were the case, would indeed be vulnerable.
Isn't it a bit harsh to downvote to -1 a comment which links to two completly on-topic libraries?
Isn't it a bit harsh to downvote to -1 a comment which links to two completly on-topic libraries?