PkgRadar

PyPI · pypi.org

neuralnode

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 2.1.14

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · neuralnode-2.1.14/scripts/setup.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · neuralnode-2.1.14/src/neuralnode/diagnostics/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · neuralnode-2.1.14/src/neuralnode/tools/system/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · neuralnode-2.1.14/src/neuralnode/tools/__init__.py
mediumPy Import Time Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · neuralnode-2.1.14/src/neuralnode/vectorstores/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · neuralnode-2.1.14/src/neuralnode/chains/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · neuralnode-2.1.14/src/neuralnode/tts/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.14High risk1902026-06-05
2.1.13High risk1902026-06-05
2.1.12High risk1902026-06-05
2.1.11High risk1902026-06-05
2.1.10High risk1902026-06-05
2.1.9High risk1902026-06-05
2.1.8High risk1902026-06-05
2.1.7High risk1902026-06-05
2.1.6High risk1902026-06-05
2.1.5High risk1902026-06-04
2.1.4High risk1902026-06-04
2.1.3High risk1902026-06-04

Block this in CI

PkgRadar gates neuralnode (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi neuralnode==2.1.14