PkgRadar

PyPI · pypi.org

geocif

Py Runtime Pickle Loads: pickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled.

Why PkgRadar flagged 0.4.705

SeveritySignalEvidence
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · geocif-0.4.705/geocif/ml/outlook.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.729Low risk02026-06-07
0.4.728Low risk02026-06-07
0.4.727Low risk02026-06-07
0.4.726Low risk02026-06-07
0.4.725Low risk02026-06-07
0.4.724Low risk02026-06-05
0.4.723Low risk02026-06-05
0.4.722Low risk02026-06-05
0.4.721Low risk02026-06-04
0.4.720Low risk02026-06-04
0.4.719Low risk02026-06-04
0.4.718Low risk02026-06-04
0.4.717Low risk02026-06-04
0.4.716Low risk02026-05-31
0.4.715Low risk02026-05-30
0.4.714Low risk02026-05-30
0.4.713Low risk02026-05-30
0.4.712Low risk02026-05-29
0.4.711Low risk02026-05-29
0.4.710Low risk02026-05-29
0.4.709Low risk02026-05-29
0.4.708Low risk02026-05-29
0.4.707Low risk02026-05-29
0.4.706Low risk02026-05-28
0.4.705Review102026-05-26
0.4.704Review102026-05-26
0.4.703Review102026-05-26

Block this in CI

PkgRadar gates geocif (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi geocif==0.4.705