PkgRadar

PyPI · pypi.org

tornado

Py Install Time Eval Exec: Python eval()/exec() called on a string.

Why PkgRadar flagged 6.5.6

SeveritySignalEvidence
mediumPy Install Time Eval ExecPython eval()/exec() called on a string. · tornado-6.5.6/setup.py
mediumRemote Payloadmatched "curl\n" · tornado-6.5.6/tornado/curl_httpclient.py
mediumRemote Payloadmatched "curl " · tornado-6.5.6/tornado/httpclient.py

Scanned versions

VersionVerdictScoreScanned (UTC)
6.5.7Low risk02026-06-08
6.5.6Review342026-05-27

Block this in CI

PkgRadar gates tornado (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi tornado==6.5.6