sci-figure
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalysci_figure/image_processor.py
LOWAnomalyLOW
sci_figure/image_processor.py
The code is a local image-saving utility with no evident malicious behavior. It has a moderate path traversal and arbitrary-file-overwrite risk because output filenames and the format extension are not sanitized before being passed to Image.save. Restrict fmt to an allowlist, reject absolute paths and separators in name/sublabel, resolve the final path, and verify it remains under output_dir. The displayed fragment also appears incomplete because it ends with 'return filepat'.
Confidence: 98%Severity: 58%
Audit Metadata