Warn
Audited by Socket on Sep 22, 2026
1 alert found:
SecuritySecurityexamples/invoice-generator.md
MEDIUMSecurityMEDIUM
examples/invoice-generator.md
The fragment is an invoice PDF generator with one critical security issue: eval(row['items']) permits arbitrary code execution from a malicious or tampered CSV. It should be replaced with a safe parser such as ast.literal_eval for trusted Python-literal formats or, preferably, JSON parsing with schema validation. The invoice_number used in output filenames should also be restricted to a safe filename format and verified to remain within output_dir. The shown code does not otherwise indicate malware or intentional sabotage.
Confidence: 98%Severity: 86%
Audit Metadata