PyPI · pypi.org
telethon-pro-safe
Py Install Time Subprocess: subprocess call with shell=True — passes argv to /bin/sh.
Early detection
PkgRadar flagged this 1h before public disclosure
Detected 2026-05-28 · disclosed as MAL-2026-4859 on 2026-05-28
Why PkgRadar flagged 3.0.1
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Install Time Subprocess | subprocess call with shell=True — passes argv to /bin/sh. · telethon_pro_safe-3.0.1/setup.py |
| medium | Py Install Time Subprocess | subprocess call — process spawning. · telethon_pro_safe-3.0.1/setup.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.0.4 | Low risk | 0 | 2026-05-28 |
3.0.3 | Low risk | 0 | 2026-05-28 |
3.0.2 | Low risk | 0 | 2026-05-28 |
3.0.1 | High risk | 100 | 2026-05-28 |
3.0.0 | High risk | 95 | 2026-05-28 |
Block this in CI
pkgradar gate --ecosystem pypi telethon-pro-safe==3.0.1