PkgRadar

PyPI · pypi.org

meutils

Py Import Time Pickle Loads: pickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled.

Why PkgRadar flagged 2026.6.11.22.46.21

SeveritySignalEvidence
mediumPy Import Time Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · meutils-2026.6.11.22.46.21/meutils/db/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · meutils-2026.6.11.22.46.21/meutils/str_utils/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · meutils-2026.6.11.22.46.21/meutils/request_utils/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · meutils-2026.6.11.22.46.21/meutils/str_utils/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.11.22.46.21High risk402026-06-11
2026.6.11.22.39.46High risk402026-06-11
2026.6.11.22.38.43High risk402026-06-11
2026.6.11.22.23.13High risk402026-06-11
2026.6.11.22.3.20High risk402026-06-11
2026.6.11.21.58.15High risk402026-06-11
2026.6.11.22.2.25High risk402026-06-11
2026.6.11.21.35.25High risk402026-06-11
2026.6.11.20.52.13High risk402026-06-11
2026.6.10.22.32.19High risk402026-06-10
2026.6.10.22.24.12High risk402026-06-10
2026.6.10.22.13.43High risk402026-06-10
2026.6.10.21.44.2High risk402026-06-10
2026.6.10.21.26.28High risk402026-06-10
2026.6.10.21.38.42High risk402026-06-10
2026.6.10.21.24.27High risk402026-06-10
2026.6.3.21.10.19High risk402026-06-03
2026.6.3.20.42.8High risk402026-06-03
2026.6.3.20.20.17High risk402026-06-03
2026.5.31.14.24.16High risk402026-05-31
2026.5.29.18.54.54High risk402026-05-30
2026.5.29.18.25.47High risk402026-05-30
2026.5.29.18.13.59High risk402026-05-30
2026.5.29.18.8.57High risk402026-05-30
2026.5.29.18.5.17High risk402026-05-30
2026.5.29.18.6.26High risk402026-05-30
2026.5.29.16.16.59High risk402026-05-30
2026.5.29.13.58.21High risk402026-05-30
2026.5.29.13.57.27High risk402026-05-30
2026.5.29.13.7.7High risk402026-05-30
2026.5.28.20.23.16High risk402026-05-30
2026.5.28.18.56.23High risk402026-05-30
2026.5.28.18.26.50High risk402026-05-30
2026.5.28.13.0.45High risk402026-05-30
2026.5.27.19.45.4High risk402026-05-30
2026.5.27.18.48.38High risk402026-05-30

Block this in CI

PkgRadar gates meutils (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi meutils==2026.6.11.22.46.21