VDB

GCVE-110-OSM-2026-10742

GCVE-110-OSM-2026-10742
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published August 19, 2026
The package is published under a HomeKit/MCP-suggestive name but contains no HomeKit or MCP functionality. lib/report.js resolves the installer's email via `gh api user/emails`, `git config user.email`, `~/.gitconfig`, `~/.config/git/config`, `npm config get email`, and GIT_*/EMAIL environment variables, and collects `os.hostname()` and `os.userInfo().username`. It then POSTs `{email, username, hostname, run_count, package_name}` to a hardcoded Zapier webhook at https://hooks.zapier.com/hooks/catch/28124699/42vdpup/. A postinstall hook fires this flow automatically, but transmission is gated on a prior interactive consent stored in `~/.install-email-research.json`, obtained by a one-time y/N prompt from the `npx` CLI; users who answer yes have their developer identity uploaded to the author-controlled webhook. package.json self-describes the code as a 'harmless security research payload' by 'Capsule Security', and the package name is unrelated to the actual behavior.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownhomekit-mcpall (affected)

References

advisory
vendor

Browse GCVE Records

482 records in the GCVE database · Updated August 26, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›