VDB
GCVE-110-OSM-2026-10767
GCVE-110-OSM-2026-10767
Advisory PublishedCVSS 5.4/10
This package appears to be an SEO squatting / typosquatting operation rather than a functional library. The publisher 'dallen' has 34 packages, all with exactly one version (0.1.0), all mimicking well-known AI brand names (Perplexity, DeepSeek, Kling, Gemini, Copilot, etc.) and all pointing to third-party websites. The package contains no actual functionality — it is purely a metadata wrapper directing users to perplexityimage.com, which is not affiliated with Perplexity AI. This pattern strongly suggests abuse of PyPI as a search-engine ranking tool or traffic redirection scheme, and possibly as a squatting operation to intercept installs by developers expecting official packages from brands like Perplexity. While no malicious code execution, exfiltration, or credential theft is present in this version, the volume and pattern of brand-impersonating packages from this publisher is itself a significant abuse signal.
ENTRY
perplexity_image/__init__.py (module-import: 66)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | perplexity-image | all (affected) | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.