VDB

GCVE-110-OSM-2026-1322

GCVE-110-OSM-2026-1322
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published April 3, 2026
Malicious VSCode tasks.json file that executes on the user device, if the repository is opened in VScode as trusted workspace. The final payloads drops JavaScript malware on the user device. This payload known establish contact with attacker controlled C2 in a defined interval.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

References

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›