I could be missing something here, but I think this is vulnerable to DO'1985, a/k/a Desmedt-Odlyzko:
https://github.com/rpgp/rpgp/blob/8e67756ebce780c91b8c2ffc7d...
In particular, in the presence of an insufficiently wide hash, the absence of padding here means that RSA signature validation is not secure under EUF-CMA. Matt Green has a great post on why and when EUF-CMA matters[1].
(This isn't necessarily this implementation's fault, since PGP seemingly (!) encourages the stripping of padding from signatures. But I can't find another source for whether this is actually encouraged by OpenPGP, or whether implementations just widely allow it.)
[1]: https://blog.cryptographyengineering.com/euf-cma-and-suf-cma...