Maven · repo1.maven.org
org.wso2.org.apache.commons:commons-vfs2
Reverse Shell, Java Dynamic Classload, Credential file access
Why PkgRadar flagged 2.10.0-wso2v8
| Severity | Signal | Evidence |
|---|---|---|
| high | Reverse Shell | org/wso2/org/apache/commons/vfs2/provider/sftp/SftpStreamProxy.java |
| medium | Java Dynamic Classload | org/wso2/org/apache/commons/vfs2/impl/VFSClassLoader.java |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.10.0-wso2v8 | High risk | 32 | 2026-06-26 |
Block this in CI
pkgradar gate --ecosystem maven org.wso2.org.apache.commons:[email protected]