VDB

GCVE-110-NPM-2026-033970

GCVE-110-NPM-2026-033970
Advisory Published
Vulnetix · Advisory published October 1, 2026
[P-BASE64] Base64 decoding (possible payload hiding) — matched: content: "---\nname: lizard-core\ndescription: \"Core Lizard CLI usage guide. Read this before running any lizard commands. Covers the full app lifecycle (login, init, link, add, up, redeploy, logs, events, status, scale, restart, secrets, domains, run, ssh, metrics), the workspace → project → s

Weaknesses (CWE)

CWE-506Embedded Malicious CodeCWE-522Insufficiently Protected CredentialsCWE-200Exposure of Sensitive Information to an Unauthorized Actor

Affected Products

VendorProductVersionsPlatforms
npm@lizard-build/cli4.0.21 (affected)—

References

advisory
web
web

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›