Maven · repo1.maven.org
cn.pivoto.polaris.toolkit:polaris-core
Java Dynamic Classload: URLClassLoader / defineClass — runs attacker-provided bytecode.
Why PkgRadar flagged 3.8.16
| Severity | Signal | Evidence |
|---|---|---|
| medium | Java Dynamic Classload | URLClassLoader / defineClass — runs attacker-provided bytecode. · io/polaris/core/asm/internal/AsmReflects.java |
| medium | Java Dynamic Classload | URLClassLoader / defineClass — runs attacker-provided bytecode. · io/polaris/core/asm/reflect/AccessClassLoader.java |
| medium | Java Dynamic Classload | URLClassLoader / defineClass — runs attacker-provided bytecode. · io/polaris/core/compiler/MemoryClassLoader.java |
| medium | Java Jndi Lookup | JNDI / Naming.lookup — remote class-loading primitive (Log4Shell family). · io/polaris/core/jdbc/Jdbcs.java |
| medium | Java Dynamic Classload | URLClassLoader / defineClass — runs attacker-provided bytecode. · io/polaris/core/asm/generator/AbstractClassGenerator.java |
| medium | Java Dynamic Classload | URLClassLoader / defineClass — runs attacker-provided bytecode. · io/polaris/core/asm/internal/ClassEmitters.java |
| medium | Java Dynamic Classload | URLClassLoader / defineClass — runs attacker-provided bytecode. · io/polaris/core/classloader/ClassLoaders.java |
| medium | Java Dynamic Classload | URLClassLoader / defineClass — runs attacker-provided bytecode. · io/polaris/core/classloader/DynamicURLClassLoader.java |
| medium | Java Unsafe Deserialize | ObjectInputStream / XStream.fromXML — untrusted deserialization sink. · io/polaris/core/io/Serializations.java |
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · io/polaris/core/os/JShells.java |
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · io/polaris/core/os/Shells.java |
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · io/polaris/core/os/TopExecutor.java |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.8.16 | Review | 70 | 2026-06-10 |
Block this in CI
pkgradar gate --ecosystem maven cn.pivoto.polaris.toolkit:[email protected]