VDB
GCVE-110-OSM-2026-10793
GCVE-110-OSM-2026-10793
Advisory PublishedCVSS 8.8/10
This crates.io package is part of the software supply chain attack on the arrayref package. This was a coordinated attack that installed an infostealer and cryptostealer.
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | aronenao | all (affected) | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.