VDB
GCVE-110-OSM-2026-10786
GCVE-110-OSM-2026-10786
Advisory PublishedCVSS 8.8/10
The build.rs file downloads a payload from a remote IP, writes it to a temporary file, and executes it using chmod on Unix or a hidden PowerShell process via VBScript on Windows.
https://23.254.165.112:9089/rust-crate_0.1.0 # Linux x86_64
408ef22050ffc5a67e005802809026b29f297a8019f8fda91a2afa8e877ba434
https://23.254.165.112:9089/rust-crate_0.2.0 # Windows x86_64
492f2ab86f8d8911adc79c10ec1541704f5311d207d9d799b0d2a57fcc6a4391
https://23.254.165.112:9089/rust-crate_0.3.0 # macOS x86_64
c9561a3b00a0fa38b7772675d987f84bd429c55cd024fc08a98245c2d1632848
https://23.254.165.112:9089/rust-crate_0.4.0 # macOS ARM64
74d3447e7cf99c99ea01a16332ec27432dfb0f491e10e67cd118065a60483306
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | proc-macro1 | all (affected) | — |
Browse GCVE Records
825 records in the GCVE database · Updated September 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.