ecommerce-reverse-product-image-search-api
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecurityscripts/nexscope_paths.py
MEDIUMSecurityMEDIUM
scripts/nexscope_paths.py
No clear malware or covert data-theft behavior is present. The code contains legitimate but security-sensitive file upload and download functionality. Main risks are unsanitized SESSION_ID path construction, arbitrary outbound HTTP(S) access through download_media(), unlimited download size, and transmission of an environment-provided API key to the configured endpoint. The fragment is syntactically incomplete as provided.
Confidence: 97%Severity: 70%
Audit Metadata