get-subtitles
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalyscripts/cli.py
LOWAnomalyLOW
scripts/cli.py
No clear malware, credential exfiltration, persistence, destructive behavior, reverse shell, or cryptomining is present in the supplied fragment. The primary security concern is unrestricted fetching of externally supplied URLs with redirects, which can cause SSRF, internal-service access, or resource exhaustion. The tool also handles API keys and performs legitimate but potentially consequential Bazarr/Radarr mutations. The fragment is syntactically incomplete and requires correction before execution. External URL fetching should enforce HTTPS, host or domain allowlists, redirect validation, private-network blocking, response-size limits, and content validation.
Confidence: 96%Severity: 62%
Audit Metadata