VDB
GCVE-110-OSM-2026-1322
GCVE-110-OSM-2026-1322
Advisory PublishedCVSS 8.8/10
Malicious VSCode tasks.json file that executes on the user device, if the repository is opened in VScode as trusted workspace.
The final payloads drops JavaScript malware on the user device.
This payload known establish contact with attacker controlled C2 in a defined interval.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Malicious package:
advisory
Browse GCVE Records
73,877 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.