VDB

GCVE-110-OSM-2026-12678

GCVE-110-OSM-2026-12678
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 28, 2026
The package's main module is an IIFE that injects a <script> element pointing at the hardcoded URL https://nee1ahnaw7.xsses.link and appends it to the document, causing whatever JavaScript that host serves to execute in the caller's page context. The destination is unpinned, opaque, unrelated to the package's declared identity or publisher, and the host name aligns with XSS/payload delivery infrastructure. Any application that bundles this dependency will fetch and execute attacker-controlled JavaScript at runtime, granting full code execution within the app's origin — enabling credential/session theft, arbitrary DOM manipulation, and further payload staging. ENTRY loader.js (main: loader.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownrai6jaisahthaghee5ou-loader-packageall (affected)—

Browse GCVE Records

3,112 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›