https://github.com/apache/poi.git
· scanned 2026-05-16 13:30 UTC (1 day, 7 hours ago)
· 10 languages
44 findings 8/10 scanners ran 17th percentile · Java · medium (20-100K LoC)
41 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 6 of 41 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
poi-examples/src/main/java/org/apache/poi/examples/xssf/streaming/SavePasswordProtectedXlsx.java:88
path_traversallegacy
poi-ooxml/src/main/java/org/apache/poi/ooxml/util/PackageHelper.java:51
path_traversallegacy
poi-ooxml/src/main/java/org/apache/poi/openxml4j/opc/OPCPackage.java:429
path_traversallegacy
poi-ooxml/src/main/java/org/apache/poi/poifs/crypt/dsig/services/TimeStampSimpleHttpClient.java:212
ssrflegacy
poi-ooxml/src/main/java/org/apache/poi/poifs/crypt/dsig/services/TSPTimeStampService.java:239
ssrflegacy
poi-ooxml/src/main/java/org/apache/poi/poifs/crypt/dsig/SignatureConfig.java:506
ssrflegacy
This page is publicly accessible at:
https://repobility.com/scan/04c8bcc5-9bd7-43c2-8ab5-56e918f8f3c4/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/04c8bcc5-9bd7-43c2-8ab5-56e918f8f3c4/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.