PkgRadar

Maven · repo1.maven.org

io.github.pquiring:javaforce

Java Unsafe Deserialize: ObjectInputStream / XStream.fromXML — untrusted deserialization sink.

Why PkgRadar flagged 111.0

SeveritySignalEvidence
mediumJava Unsafe DeserializeObjectInputStream / XStream.fromXML — untrusted deserialization sink. · javaforce/media/Music.java
mediumJava Unsafe DeserializeObjectInputStream / XStream.fromXML — untrusted deserialization sink. · javaforce/Compression.java
mediumJava Unsafe DeserializeObjectInputStream / XStream.fromXML — untrusted deserialization sink. · javaforce/JF.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · javaforce/JFClassLoader.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · javaforce/JF.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · javaforce/KeyMgmt.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · javaforce/ShellProcess.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · javaforce/awt/VNCServer.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · javaforce/jni/lnx/LnxPty.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · javaforce/linux/Linux.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · javaforce/service/ProxyServer.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · javaforce/utils/Package.java

Scanned versions

VersionVerdictScoreScanned (UTC)
111.0Review602026-06-10

Block this in CI

PkgRadar gates io.github.pquiring:javaforce (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven io.github.pquiring:[email protected]