VDB
GCVE-110-OSM-2026-12713
GCVE-110-OSM-2026-12713
Advisory PublishedCVSS 5.4/10
package.json declares a dependency `test-supply-npm-git-prepare-proof-4` whose value is a bare git URL (`git+https://git@github.com/agustedone/test-supply-npm-git-prepare-proof-4.git`) rather than a registry version range. On `npm install`, npm clones that repository at mutable HEAD and runs any lifecycle scripts (preinstall/install/postinstall/prepare) it contains, with no version pin, no commit SHA, and no integrity check. Whoever controls the referenced GitHub repository controls code that executes on the installer's machine at install time. The shipped package body is otherwise an inert stub — the manifest line itself is the delivery mechanism.
ENTRY
index.js (main: index.js)
- URL-Based Dependency in package.json: ""dependencies": { "test-supply-npm-git-prepare-proof-4": "git+https://git@github..."
ADDITIONAL FINDINGS
- Brand New Package
- Publisher Shows Burner-Account Pattern
- Rapid Version Publishing
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | test-supply-npm-lib-4 | all (affected) | — |
Aliases
Browse GCVE Records
3,112 records in the GCVE database · Updated October 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.