VDB

GCVE-110-OSM-2026-11244

GCVE-110-OSM-2026-11244
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published August 28, 2026
Bulk-published npm package containing a deceptive unblocked-games browser. It loads provider-controlled game catalogs and remote HTML into browser frames and disguised pop-up windows. No npm lifecycle hooks, host-level code execution, persistence, credential theft, or data exfiltration were found in version 1.0.0. The package exports an embedded HTML application. On page load it fetches a remote game catalog, while user-selected providers trigger additional catalog and GitHub API requests. Catalog-controlled HTML can be fetched and rendered through Blob URLs, injected into an about:blank pop-up styled as Google Drive, or loaded directly into an iframe when fetching fails. A download button can save fetched remote HTML or an iframe wrapper as a local HTML file. The downstream remote pages are mutable and were not retrieved, so their scripts, advertising, tracking, and additional payload behavior remain unconfirmed. The package has no install scripts, dependencies, subprocess launchers, filesystem writes, native payloads, persistence, blockchain activity, or confirmed exfiltration behavior.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownsecure-test-browser-5pst58e31.0.0 (affected)

References

advisory
vendor

Browse GCVE Records

831 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›