VDB

GCVE-110-OSM-2026-10769

GCVE-110-OSM-2026-10769
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published August 19, 2026
This package is almost certainly SEO spam / PyPI namespace squatting rather than active malware. The publisher 'dallen' has 34 packages, all single-version 0.1.0 entries with AI-product-themed names and no downloads, following a clear pattern of registering PyPI names that mirror popular AI brand names (seedream5-ai, kling3-ai, deepseek-video, gemini-omni-ai, etc.) to point traffic at third-party sites. The entrypoint code is completely innocuous — it sets metadata strings and defines a get_info() function with no network calls, file reads, or code execution. The IOCs are limited to the homepage URL seedream5ai.org appearing in package metadata only, with a passive role. There is no exfiltration, obfuscation, credential theft, or install hook activity. The risk is namespace squatting and potential phishing/SEO manipulation rather than supply-chain compromise. ENTRY seedream5_ai/__init__.py (module-import: 12)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownseedream5-aiall (affected)

References

vendor

Browse GCVE Records

3,530 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›