**Description of the false positive** I use regex to handle the Path Injection. **URL to the alert on the project page on LGTM.com** https://lgtm.com/projects/g/Deasilsoft/a2j/snapshot/1257a1ab48aaa9ea4a564dc93ca45e4c0a817c18/files/src/a2j/util.py?sort=name&dir=ASC&mode=heatmap#x20ee52e2c34e65c0:1