PkgRadar

PyPI · pypi.org

large-image

Py Runtime Pickle Loads: pickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled.

Why PkgRadar flagged 1.34.2.dev20

SeveritySignalEvidence
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · large_image-1.34.2.dev20/large_image/cache_util/rediscache.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.34.3.dev4Low risk02026-06-04
1.34.3.dev2Low risk02026-06-04
1.34.3a171Low risk02026-06-02
1.34.2Low risk02026-06-02
1.34.2.dev28Low risk02026-06-01
1.34.2.dev26Low risk02026-06-01
1.34.2.dev24Low risk02026-05-28
1.34.2.dev22Low risk02026-05-28
1.34.2.dev20Review62026-05-26

Block this in CI

PkgRadar gates large-image (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi large-image==1.34.2.dev20