VDB

GCVE-110-OSM-2026-10787

GCVE-110-OSM-2026-10787
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 21, 2026
This crates.io package was part of the coordinated software supply chain attack on the arrayref package. The maintainer droundy was compromised and several of their crates were compromised with new malicious dependencies. This crate is one of those new malicious dependencies. Installs a malicious dependency which injects malware during build time

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownaroneall (affected)

References

vendor

Browse GCVE Records

831 records in the GCVE database · Updated September 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›