VDB
GCVE-110-OSM-2026-10769
GCVE-110-OSM-2026-10769
Advisory PublishedCVSS 5.4/10
This package is almost certainly SEO spam / PyPI namespace squatting rather than active malware. The publisher 'dallen' has 34 packages, all single-version 0.1.0 entries with AI-product-themed names and no downloads, following a clear pattern of registering PyPI names that mirror popular AI brand names (seedream5-ai, kling3-ai, deepseek-video, gemini-omni-ai, etc.) to point traffic at third-party sites. The entrypoint code is completely innocuous — it sets metadata strings and defines a get_info() function with no network calls, file reads, or code execution. The IOCs are limited to the homepage URL seedream5ai.org appearing in package metadata only, with a passive role. There is no exfiltration, obfuscation, credential theft, or install hook activity. The risk is namespace squatting and potential phishing/SEO manipulation rather than supply-chain compromise.
ENTRY
seedream5_ai/__init__.py (module-import: 12)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | seedream5-ai | all (affected) | — |
Browse GCVE Records
3,530 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.