VDB
GCVE-110-OSM-2026-12402
GCVE-110-OSM-2026-12402
Advisory PublishedCVSS 9.6/10
PolinRider malware fork of rails/rails (58,775 stars) with an ACTIVE OPEN pull request (#57292) carrying a payload into the upstream project, using a previously-undocumented marker variant (global.i="A#-" instead of the known global['!']/global['_V']/globalThis.i= markers). The PR camouflages the payload inside a real-looking ActiveModel bugfix (.gitignore, activemodel/lib/active_model/attributes.rb, activemodel/test/cases/attributes_test.rb changes are legitimate-looking), with the malicious code appended to eslint.config.mjs.
=== UPSTREAM INJECTION ATTEMPT (ACTIVE OPEN PR) ===
Attack type: Fork-and-PR upstream injection
Fork repo: notorious94/rails
Parent repo: rails/rails (58,775 stars)
Fork created: 2026-05-03
=== PAYLOAD ===
Infected file: eslint.config.mjs
Signature: new variant marker global.i="A#-..." (javascript-obfuscator.io-style hex/opcode packing, internally remaps to global['_V']), verified present at PR head commit 041fecf3
Not caught by any previously-documented PolinRider signature (v1 rmcej%otb%/_$_1e42, v2 global['_V'], v3 globalThis.i=) - this uses global.i= (not globalThis.i=) as the outer marker.
=== PR STATUS ===
PR #57292 "fix: ActiveModel::Attributes method override precedence regression" to rails/rails: OPEN since 2026-05-03, still open as of 2026-09-19
PR bundles a real-looking ActiveModel bugfix with the malicious eslint.config.mjs change - textbook camouflage
Parent infected: No (near miss, but PR is live and mergeable at any time)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
264 records in the GCVE database · Updated September 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.