VDB

GCVE-110-OSM-2026-10690

GCVE-110-OSM-2026-10690
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published August 18, 2026
This package is a PyPI-hosted SEO backlink spam operation, not traditional malware. The package contains no executable Python code (entrypoint is null); its sole content is a massive curated list of URLs (74KB+ PKG-INFO, backlink-references.json) pointing to hundreds of third-party sites, URL shorteners, paste sites, and link aggregators — all designed to build SEO link equity for formy3d.com, trellis-2.net, and related AI-tool landing pages. The publisher 'dallen' runs 34 essentially identical single-version packages (formy3d, trellis2-ai, copilot3d-ai, etc.) following the same pattern, constituting a coordinated PyPI abuse campaign. There is no real payload. Just spam links.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknowntrellis2-3d-infoall (affected)

References

vendor

Browse GCVE Records

831 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›