VDB

GCVE-110-OSM-2026-10132

GCVE-110-OSM-2026-10132
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published August 9, 2026
The package is explicitly designed as a CTF flag stealer masquerading as a cubesat driver library. The entrypoint `cubesat_upstream_driver/__init__.py` contains a function `_exfil_flag()` that runs unconditionally at import time, systematically reading common flag file paths (/flag, /flag.txt, /root/flag.txt, /app/flag.txt, etc.), glob-scanning for flag-like files across the filesystem, and harvesting environment variables containing keywords like 'flag', 'secret', 'ctf', 'key', or 'token' — falling back to dumping the entire environment. The result is stored in `_BOOT_SECRET` at module load time and re-executed on every `handle_command()` call. Although no exfil transport (webhook/HTTP POST) was captured in this scan, the data collection is clearly adversarial — targeting CTF infrastructure or CI/CD secrets — and the transport may occur in a later stage or via the calling context. The publisher account 'jennysclady13' has one package, zero history, and the repository reference is fabricated. ENTRY cubesat_upstream_driver/__init__.py (module-import: 34)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknowncubesat-upstream-driverall (affected)

References

vendor
advisory

Browse GCVE Records

67,407 records in the GCVE database · Updated August 11, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›