PkgRadar

PyPI · pypi.org

lollms-client

Py Import Time Subprocess: subprocess call with shell=True — passes argv to /bin/sh.

Why PkgRadar flagged 1.14.22

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call with shell=True — passes argv to /bin/sh. · lollms_client-1.14.22/src/lollms_client/llm_bindings/ollama/__init__.py
highPy Import Time Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · lollms_client-1.14.22/src/lollms_client/tti_bindings/diffusers/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · lollms_client-1.14.22/src/lollms_client/llm_bindings/llama_cpp_server/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · lollms_client-1.14.22/src/lollms_client/llm_bindings/ollama/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · lollms_client-1.14.22/src/lollms_client/stt_bindings/whispercpp/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · lollms_client-1.14.22/src/lollms_client/tti_bindings/diffusers/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · lollms_client-1.14.22/src/lollms_client/tti_bindings/gguf_diffusion/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · lollms_client-1.14.22/src/lollms_client/tts_bindings/FishSpeech/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · lollms_client-1.14.22/src/lollms_client/tts_bindings/bark/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · lollms_client-1.14.22/src/lollms_client/tts_bindings/piper_tts/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · lollms_client-1.14.22/src/lollms_client/tts_bindings/vibevoice/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · lollms_client-1.14.22/src/lollms_client/tts_bindings/vllm_omni/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.14.22High risk1442026-06-12
1.14.21High risk1442026-06-11
1.14.20High risk1442026-06-10
1.14.19High risk1442026-06-10
1.14.18High risk1442026-06-10
1.14.16High risk1442026-06-10
1.14.17High risk1442026-06-10
1.14.15High risk1442026-06-08
1.14.14High risk1442026-06-08
1.14.13High risk1442026-06-08
1.14.12High risk1442026-06-05
1.14.11High risk1442026-06-04
1.14.10High risk1442026-06-02
1.14.9High risk1442026-06-01
1.14.8High risk1442026-05-31
1.14.7High risk1442026-05-31
1.14.6High risk1442026-05-31
1.14.5High risk1442026-05-30
1.14.4High risk1442026-05-30
1.14.2High risk1442026-05-30
1.14.1High risk1442026-05-30

Block this in CI

PkgRadar gates lollms-client (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi lollms-client==1.14.22