The build script in the portaudio crate will attempt to download via HTTP the portaudio source and build it.
A Mallory in the middle can intercept the download with their own archive and get RCE.
{ "license": "CC0-1.0" }
{ "affects": { "functions": [], "os": [], "arch": [] }, "affected_functions": null }
{ "cvss": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "categories": [], "informational": null }