PkgRadar

PyPI · pypi.org

esypro

Py Import Time Pickle Loads: pickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled.

Why PkgRadar flagged 39.2026.6.9.10.51

SeveritySignalEvidence
mediumPy Import Time Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · esypro-39.2026.6.9.10.51/esypro/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
39.2026.6.9.10.51Review122026-06-09
39.2026.6.9.10.28Review122026-06-09
39.2026.6.9.10.8Review122026-06-09
39.2026.6.9.9.49Review122026-06-09
39.2026.6.9.9.40Review122026-06-09

Block this in CI

PkgRadar gates esypro (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi esypro==39.2026.6.9.10.51