VDB
GCVE-110-NPM-2026-013743
GCVE-110-NPM-2026-013743
Advisory Published
The npm package `@cachly-dev/mcp-server` (version 0.10.169) was flagged as malicious by automated package analysis (5 corroborating detection(s)). Installing it may execute attacker-controlled code via lifecycle scripts or bundled JavaScript. Verdict path: evidence — for ownership-only paths (owner-known-bad / multi-identity) the change of ownership is a compounding indicator the engine correlated with other signals, not standalone proof. This verdict is produced by static analysis and is subject to human review.
Weaknesses (CWE)
CWE-506Embedded Malicious CodeCWE-200Exposure of Sensitive Information to an Unauthorized Actor
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| npm | @cachly-dev/mcp-server | 0.10.118 (affected), 0.10.130 (affected), 0.10.131 (affected), 0.10.132 (affected), 0.10.133 (affected), 0.10.134 (affected), 0.10.139 (affected), 0.10.140 (affected), 0.10.142 (affected), 0.10.141 (affected), 0.10.146 (affected), 0.10.150 (affected), 0.10.153 (affected), 0.10.161 (affected), 0.10.165 (affected), 0.10.163 (affected), 0.10.164 (affected), 0.10.167 (affected), 0.10.168 (affected), 0.10.169 (affected) | — |
Browse GCVE Records
1,837 records in the GCVE database · Updated September 7, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.