VDB

GCVE-110-OSM-2025-1100

GCVE-110-OSM-2025-1100
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 21, 2025
PolinRider malware injected via open PR #8 into AdwelloTech/odoo-clone frontend config files. === UPSTREAM INJECTION ATTEMPT (ACTIVE OPEN PR) === Repo: AdwelloTech/odoo-clone Infected files: frontend/eslint.config.mjs, frontend/next.config.js, frontend/next.config.ts, frontend/postcss.config.js, frontend/postcss.config.mjs Signature: v3-style global.i="A9-..." marker + global['m']/global['r'] require/module hijack === PR STATUS === PR #8: OPEN, not merged.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

264 records in the GCVE database · Updated September 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›