It is identified in that we call "cmd.exe" without specifying the exact path, and that in the event a cmd.exe exists in the working directory, that will be run instead. This can be a trip hazard when working with dangerous material.

PySystemState is blamed in the reference, but a search shows that we mention cmd.exe in the posix module too. And there we should consider removing too :)

Almost certainly, the right answer is to use COMSPEC to find it, compare the  standard library . In CPython that falls back to "cmd.exe" if COMSPEC is not defined. In Jython it uses the list ultimately defined in enum OS .
