elixir-security-review
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecurityreferences/code-injection.md
MEDIUMSecurityMEDIUM
references/code-injection.md
The code is security guidance containing explicitly vulnerable examples. Code.eval_string/1 on external input is a critical arbitrary-code-execution pattern, and binary_to_term/1 without [:safe] is unsafe for untrusted data. Dynamic module resolution from input should be replaced by the provided fixed allowlist. The fragment itself shows no malware, exfiltration, persistence, or obfuscation; risk applies if the vulnerable examples are deployed.
Confidence: 98%Severity: 88%
Audit Metadata