Runtime.getRuntime().exec called with a concatenated string permits command injection.
Avoid shell invocation; pass a fixed command with an argument array and validate all inputs.