VDB

GCVE-110-OSM-2026-10786

GCVE-110-OSM-2026-10786
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 20, 2026
The build.rs file downloads a payload from a remote IP, writes it to a temporary file, and executes it using chmod on Unix or a hidden PowerShell process via VBScript on Windows. https://23.254.165.112:9089/rust-crate_0.1.0 # Linux x86_64 408ef22050ffc5a67e005802809026b29f297a8019f8fda91a2afa8e877ba434 https://23.254.165.112:9089/rust-crate_0.2.0 # Windows x86_64 492f2ab86f8d8911adc79c10ec1541704f5311d207d9d799b0d2a57fcc6a4391 https://23.254.165.112:9089/rust-crate_0.3.0 # macOS x86_64 c9561a3b00a0fa38b7772675d987f84bd429c55cd024fc08a98245c2d1632848 https://23.254.165.112:9089/rust-crate_0.4.0 # macOS ARM64 74d3447e7cf99c99ea01a16332ec27432dfb0f491e10e67cd118065a60483306

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownproc-macro1all (affected)

References

vendor

Browse GCVE Records

825 records in the GCVE database · Updated September 1, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›