VDB
GCVE-110-OSM-2026-11244
GCVE-110-OSM-2026-11244
Advisory PublishedCVSS 5.4/10
Bulk-published npm package containing a deceptive unblocked-games browser. It loads provider-controlled game catalogs and remote HTML into browser frames and disguised pop-up windows. No npm lifecycle hooks, host-level code execution, persistence, credential theft, or data exfiltration were found in version 1.0.0.
The package exports an embedded HTML application. On page load it fetches a remote game catalog, while user-selected providers trigger additional catalog and GitHub API requests. Catalog-controlled HTML can be fetched and rendered through Blob URLs, injected into an about:blank pop-up styled as Google Drive, or loaded directly into an iframe when fetching fails. A download button can save fetched remote HTML or an iframe wrapper as a local HTML file. The downstream remote pages are mutable and were not retrieved, so their scripts, advertising, tracking, and additional payload behavior remain unconfirmed. The package has no install scripts, dependencies, subprocess launchers, filesystem writes, native payloads, persistence, blockchain activity, or confirmed exfiltration behavior.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | secure-test-browser-5pst58e3 | 1.0.0 (affected) | — |
Aliases
Browse GCVE Records
831 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.