blender

Fail

Audited by Socket on Aug 3, 2026

1 alert found:

Malware
MalwareHIGH
scripts/blender-bridge.py

This module is a high-impact localhost HTTP bridge that functions as an explicit unauthenticated code-execution interface: /run accepts caller-supplied Python (or reads it from an attacker-supplied file path) and executes it via exec() in Blender’s main process with access to bpy and os. The access-control mechanism is header-based and not an effective authorization boundary. It also enables filesystem and render output side effects and returns internal state and tracebacks over HTTP. Treat as extremely suspicious/unsafe for any environment where untrusted local code could reach the listening port.

Confidence: 85%Severity: 97%
Audit Metadata
Analyzed At
Aug 3, 2026, 08:37 PM
Package URL
pkg:socket/skills-sh/jablonkai%2Fskills%2Fblender%2F@524cddbebf23446772840c4d27293d42174f328d9ab32a0d3f03892204973010
Security Audit — socket — blender