PkgRadar

Maven · repo1.maven.org

com.actelion.research:openchemlib

Java Unsafe Deserialize: ObjectInputStream / XStream.fromXML — untrusted deserialization sink.

Why PkgRadar flagged 2026.6.1

SeveritySignalEvidence
mediumJava Unsafe DeserializeObjectInputStream / XStream.fromXML — untrusted deserialization sink. · com/actelion/research/gui/clipboard/ClipboardHandler.java
mediumJava Unsafe DeserializeObjectInputStream / XStream.fromXML — untrusted deserialization sink. · com/actelion/research/calc/Matrix.java
mediumJava Unsafe DeserializeObjectInputStream / XStream.fromXML — untrusted deserialization sink. · com/actelion/research/util/IOCL.java
mediumJava Unsafe DeserializeObjectInputStream / XStream.fromXML — untrusted deserialization sink. · com/actelion/research/util/Base64.java
mediumJava Unsafe DeserializeObjectInputStream / XStream.fromXML — untrusted deserialization sink. · com/actelion/research/chem/Molecule3DFunctions.java
mediumJava Unsafe DeserializeObjectInputStream / XStream.fromXML — untrusted deserialization sink. · org/openmolecules/chem/interaction/rf/RFKnowledgeBase.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · com/actelion/research/util/Platform.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · com/actelion/research/util/BrowserControl.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · com/actelion/research/gui/hidpi/HiDPIHelper.java

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.1Review282026-06-13

Block this in CI

PkgRadar gates com.actelion.research:openchemlib (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven com.actelion.research:[email protected]