VDB

GCVE-110-OSM-2026-11263

GCVE-110-OSM-2026-11263
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 29, 2026
Malicious VSCode tasks.json file and malicious code that delivers malware to user device. At the time of this report, the tasks.json hosted infrastructure is inactive. However, the secondary payload hidden in .env file is still active, that exfiltrates environment variable to attacker controlled API when the application is executed.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

1,469 records in the GCVE database · Updated September 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›