create-svg
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalysrc/create_svg/io.py
LOWAnomalyLOW
src/create_svg/io.py
The code appears to be a conventional YAML/resource loader and contains no evident malware. The primary security concern is path traversal or arbitrary file disclosure when theme references, base directories, scene paths, or template names are influenced by untrusted input. Restrict paths to approved project directories and validate names as safe relative filenames before use. `yaml.safe_load()` reduces deserialization risk. The shown fragment also appears incomplete at the final function expression.
Confidence: 97%Severity: 57%
Audit Metadata