PyPI · pypi.org
praisonai
Py Install Time Subprocess: subprocess call — process spawning.
Why PkgRadar flagged 4.6.58
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Install Time Subprocess | subprocess call — process spawning. · praisonai-4.6.58/praisonai/cli/commands/setup.py |
| medium | Py Install Time Subprocess | subprocess call — process spawning. · praisonai-4.6.58/praisonai/setup.py |
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · praisonai-4.6.58/praisonai/cli/features/mcp.py |
| medium | Py Import Time Subprocess | subprocess call — process spawning. · praisonai-4.6.58/praisonai/flow/__init__.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · praisonai-4.6.58/praisonai/browser/cli.py |
| medium | Credential file access | matched "GOOGLE_APPLICATION_CREDENTIALS" · praisonai-4.6.58/praisonai/persistence/state/firestore.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
4.6.58 | High risk | 96 | 2026-06-13 |
4.6.57 | High risk | 96 | 2026-06-13 |
4.6.56 | High risk | 96 | 2026-06-12 |
4.6.55 | High risk | 96 | 2026-06-12 |
4.6.54 | High risk | 96 | 2026-06-12 |
4.6.53 | High risk | 96 | 2026-06-12 |
4.6.52 | High risk | 76 | 2026-06-03 |
4.6.51 | High risk | 76 | 2026-06-02 |
4.6.50 | High risk | 76 | 2026-06-02 |
4.6.48 | High risk | 76 | 2026-05-30 |
4.6.47 | High risk | 76 | 2026-05-30 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem pypi praisonai==4.6.58