VDB
GCVE-110-OSM-2026-12385
GCVE-110-OSM-2026-12385
Advisory PublishedCVSS 5.4/10
PolinRider malware was merged into intelli-verse-x/n8n (a personal fork/working copy, not the real n8n/n8n project) tailwind.config.js files and subsequently removed via a self-remediation PR. Same account (anideebee7) also had confirmed infections in intelli-verse-x/vibe-kanban-fork and intelli-verse-x/cattr-server-fork-archive.
=== CONFIRMED UPSTREAM INFECTION - HISTORICAL, SELF-REMEDIATED, PERSONAL FORK NETWORK ===
Repo: intelli-verse-x/n8n (personal fork, not real n8n/n8n)
Infected files: packages/frontend/@n8n/design-system/tailwind.config.js, packages/frontend/editor-ui/tailwind.config.js
Evidence: merged PR #3 "fix(editor): Remove concealed obfuscated payload from build-executed config" (author anideebee7). Same account also fixed intelli-verse-x/vibe-kanban-fork (open PR #5, security removal) and intelli-verse-x/cattr-server-fork-archive PR #2 - this developer's entire personal fork network appears repeatedly compromised, likely via a shared local dev tool/dependency rather than a targeted upstream attack.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
264 records in the GCVE database · Updated September 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.