VDB

GCVE-110-OSM-2026-10791

GCVE-110-OSM-2026-10791
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 21, 2026
This crates.io package was part of the coordinated software supply chain attack on the popular arrayref crate. The maintainer droundy was compromised by threat actors who added several new malicious dependencies to existing popular packages. This is one of the new malicious dependencies. https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowntinymemberall (affected)

References

vendor

Browse GCVE Records

3,587 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›