VDB

GCVE-110-OSM-2026-12713

GCVE-110-OSM-2026-12713
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 30, 2026
package.json declares a dependency `test-supply-npm-git-prepare-proof-4` whose value is a bare git URL (`git+https://git@github.com/agustedone/test-supply-npm-git-prepare-proof-4.git`) rather than a registry version range. On `npm install`, npm clones that repository at mutable HEAD and runs any lifecycle scripts (preinstall/install/postinstall/prepare) it contains, with no version pin, no commit SHA, and no integrity check. Whoever controls the referenced GitHub repository controls code that executes on the installer's machine at install time. The shipped package body is otherwise an inert stub — the manifest line itself is the delivery mechanism. ENTRY index.js (main: index.js) - URL-Based Dependency in package.json: ""dependencies": { "test-supply-npm-git-prepare-proof-4": "git+https://git@github..." ADDITIONAL FINDINGS - Brand New Package - Publisher Shows Burner-Account Pattern - Rapid Version Publishing

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknowntest-supply-npm-lib-4all (affected)—

References

advisory
vendor

Browse GCVE Records

3,112 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›