PkgRadar

Maven · repo1.maven.org

com.zezeno:zeze-java

Java Dynamic Classload: URLClassLoader / defineClass — runs attacker-provided bytecode.

Why PkgRadar flagged 1.6.3

SeveritySignalEvidence
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · Zeze/Hot/HotManager.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · Zeze/Hot/HotModule.java
mediumJava Unsafe DeserializeObjectInputStream / XStream.fromXML — untrusted deserialization sink. · Zeze/Serialize/IByteBuffer.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · Zeze/Services/RunClassServer.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · Zeze/Util/InMemoryJavaCompiler.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · Zeze/Services/Daemon.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · Zeze/Services/ServiceManager/ExporterNginxConfig.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · Zeze/Services/ZokerImpl/ServiceManager.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · Zeze/Util/ClassReloader.java
mediumRemote Payloadmatched "wGet " · Zeze/Dbh2/Dbh2StateMachine.java

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.3Review1322026-06-11

Block this in CI

PkgRadar gates com.zezeno:zeze-java (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven com.zezeno:[email protected]