VDB

GCVE-110-OSM-2026-11453

GCVE-110-OSM-2026-11453
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 1, 2026
This package is a dependency confusion attempt by a presumed security researcher. From the manifest file: This package is a proof of concept used by Doyensec LLC to conduct a research. It has been uploaded for test purposes only. Its only function is to confirm the installation of the package on victim's machines. The code is not malicious in any way and will be deleted after the research survey has been concluded. Doyensec LLC does not accept any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this package. Security researcher: Doyensec LLC info@doyensec.com Payload exfils hostname to a burcollaborator.net endpoint

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknowndunnhumby-component-libraryall (affected)

References

advisory
vendor

Browse GCVE Records

3,521 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›