VDB

GCVE-110-OSM-2026-12385

GCVE-110-OSM-2026-12385
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published January 1, 2026
PolinRider malware was merged into intelli-verse-x/n8n (a personal fork/working copy, not the real n8n/n8n project) tailwind.config.js files and subsequently removed via a self-remediation PR. Same account (anideebee7) also had confirmed infections in intelli-verse-x/vibe-kanban-fork and intelli-verse-x/cattr-server-fork-archive. === CONFIRMED UPSTREAM INFECTION - HISTORICAL, SELF-REMEDIATED, PERSONAL FORK NETWORK === Repo: intelli-verse-x/n8n (personal fork, not real n8n/n8n) Infected files: packages/frontend/@n8n/design-system/tailwind.config.js, packages/frontend/editor-ui/tailwind.config.js Evidence: merged PR #3 "fix(editor): Remove concealed obfuscated payload from build-executed config" (author anideebee7). Same account also fixed intelli-verse-x/vibe-kanban-fork (open PR #5, security removal) and intelli-verse-x/cattr-server-fork-archive PR #2 - this developer's entire personal fork network appears repeatedly compromised, likely via a shared local dev tool/dependency rather than a targeted upstream attack.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

264 records in the GCVE database · Updated September 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›