VDB

GCVE-110-CARGO-2026-005890

GCVE-110-CARGO-2026-005890
Advisory Published
Vulnetix · Advisory published October 5, 2026
The crates.io crate `mobiler` (version 0.66.0) was flagged as malicious by automated package analysis (2 corroborating detection(s)). Installing it may execute attacker-controlled code via its build.rs build script or bundled Rust source. Verdict path: evidence — for ownership-only paths (owner-known-bad / multi-identity) the change of ownership is a compounding indicator the engine correlated with other signals, not standalone proof. This verdict is produced by static analysis and is subject to human review.

Weaknesses (CWE)

CWE-94Improper Control of Generation of Code ('Code Injection')CWE-506Embedded Malicious Code

Affected Products

VendorProductVersionsPlatforms
cargomobiler0.60.2 (affected), 0.61.0 (affected), 0.62.0 (affected), 0.63.0 (affected), 0.64.0 (affected), 0.64.1 (affected), 0.65.3 (affected), 0.66.0 (affected)—

References

advisory
web

Browse GCVE Records

3,244 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›