PkgRadar

PyPI · pypi.org

torch-candle

Py Import Time Pickle Loads: pickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled.

Why PkgRadar flagged 2026.6.9

SeveritySignalEvidence
mediumPy Import Time Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · torch_candle-2026.6.9/src/torch_candle/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.9Review242026-06-13
2026.6.8Review242026-06-13
2026.6.7Review342026-06-13
2026.6.6Review242026-06-13
2026.6.5Review242026-06-12
2026.6.4Review242026-06-12
2026.6.3Review242026-06-11
2026.6.2Review242026-06-10
2026.6.1Review342026-06-05
0.1.1Review242026-06-05
0.1.0Review242026-06-03

Block this in CI

PkgRadar gates torch-candle (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi torch-candle==2026.6.9