VDB

GCVE-110-OSM-2026-11418

GCVE-110-OSM-2026-11418
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published August 31, 2026
CyberOsint is used to steal and expose personal information, impersonate legitimate services to trick victims, and repeatedly spam or harass people through different platforms such as Telegram. Although setup.py is clean, during installation process it invokes main.py, which retrieves leaked personal data, spams targets through Telegram, and uses a fake verification bot to collect victims’ details. All malicious functionality resides in CyberOsint/main.py and executes at runtime when the cyberosint console script is invoked. CyberOsint (v0.4) is a harassment/doxxing toolkit disguised as an OSINT tool. Its runtime code (CyberOsint/main.py) queries a third-party breach API (server.leakosint.com) to pull leaked personal records on individuals; includes a perform_attack "bombing" function that loops requests against Telegram and Discord auth endpoints to spam a target's phone number; and runs a "TgPhisher / Eye of God" Telegram bot that fakes a "confirm your phone number" prompt and forwards the victim's phone number, Telegram ID, name, and username to the operator. Authored under the handle "TheCyberStalker" (thecyberstalker@gmail.com), with in-code Russian strings that read as doxxing threats. The package facilitates harassment, phishing, and unauthorized collection/exposure of personal data, warranting removal.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownCyberOsintall (affected)

References

vendor

Browse GCVE Records

3,587 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›