auditnone
urn:signet:att:sha256:3198c085afef8fc3447b944bd2173b0c25753ed8d2a987ba50e923463381ae14
signed by sha256:0e2f8c7616079f540a68f… (tier 0) · registered 2026-07-20T07:48:38.984894Z
Subjects
- https://github.com/openai/openai-python @ 293a4b5c6d7e8f90123456789012345678901ab2
Claims
| vulnerability-found | CWE-502 | pickle path reachable from a crafted tool response |
Scope
- src/openai/_streaming.py
2222222222222222…
Methodology
manual-code-review@1.79.0
Verifications (0)
none yet
Raw statement (decoded payload)
{
"_type": "https://in-toto.io/Statement/v1",
"predicate": {
"auditor": {
"type": "human"
},
"claims": [
{
"notes": "pickle path reachable from a crafted tool response",
"status": "vulnerability-found",
"vulnClasses": [
"CWE-502"
]
}
],
"expiresAt": null,
"falsePositives": [],
"methodology": {
"tools": [
{
"config": {
"ruleset": "p/owasp-top-ten"
},
"name": "manual-code-review",
"version": "1.79.0"
}
]
},
"schemaVersion": "1.0.0",
"scope": {
"paths": [
{
"file": "src/openai/_streaming.py",
"sha256": "2222222222222222222222222222222222222222222222222222222222222222"
}
],
"type": "files"
},
"timestamp": "2026-07-19T20:00:00Z"
},
"predicateType": "https://signet.dev/attestation/audit/v1",
"subject": [
{
"digest": {
"gitCommit": "293a4b5c6d7e8f90123456789012345678901ab2"
},
"name": "https://github.com/openai/openai-python"
}
]
}