VDB
GCVE-110-OSM-2026-10690
GCVE-110-OSM-2026-10690
Advisory PublishedCVSS 5.4/10
This package is a PyPI-hosted SEO backlink spam operation, not traditional malware. The package contains no executable Python code (entrypoint is null); its sole content is a massive curated list of URLs (74KB+ PKG-INFO, backlink-references.json) pointing to hundreds of third-party sites, URL shorteners, paste sites, and link aggregators — all designed to build SEO link equity for formy3d.com, trellis-2.net, and related AI-tool landing pages. The publisher 'dallen' runs 34 essentially identical single-version packages (formy3d, trellis2-ai, copilot3d-ai, etc.) following the same pattern, constituting a coordinated PyPI abuse campaign.
There is no real payload. Just spam links.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | trellis2-3d-info | all (affected) | — |
Browse GCVE Records
831 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.