VDB

GCVE-110-OSM-2026-10646

GCVE-110-OSM-2026-10646
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 17, 2026
This GitHub repository has been compromised as part of the PolinRider ongoing attack. Do not install or trust this repo. When you open this go module with VSCode it executes a malicious payload pretending to be a font file at

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowngithub.com/JizongL/go_with_gamev0.0.0-20200315203207-6e1a672fb302 (affected)

Browse GCVE Records

831 records in the GCVE database · Updated September 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›