VDB

GCVE-110-OSM-2026-11448

GCVE-110-OSM-2026-11448
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 1, 2026
Package exfiltrates system information to a URL controlled by the attacker The package.json file has both pre and post install properties that directly call an oastify.com endpoint. Username, network interfaces, IP address, and current working directory are all exfiltrated.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownbaidu-src-test3all (affected)

References

advisory
vendor

Browse GCVE Records

1,469 records in the GCVE database · Updated September 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›