VDB

GCVE-110-NPM-2026-034030

GCVE-110-NPM-2026-034030
Advisory Published
Vulnetix · Advisory published October 4, 2026
[P-EVAL-BASE64] Base64-decoded payload executed via eval — matched: "use strict";var O_=Object.create;var Kn=Object.defineProperty;var I_=Object.getOwnPropertyDescriptor;var x_=Object.getOwnPropertyNames;var N_=Object.getPrototypeOf,j_=Object.prototype.hasOwnProperty;var et=(e,t)=>()=>{try{return t||e((t={exports:{}}).exports,t),t.exports}catch(r){throw t=0,r}},Gn=(

Weaknesses (CWE)

CWE-506Embedded Malicious CodeCWE-200Exposure of Sensitive Information to an Unauthorized Actor

Affected Products

VendorProductVersionsPlatforms
npm@agent-sh/computer-use-linux0.7.10 (affected), 0.7.11 (affected)—

References

advisory
web
web

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›