VDB

GCVE-110-OSM-2026-13233

GCVE-110-OSM-2026-13233
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published October 5, 2026
The package fires a canarytokens.com beacon on every import via `_canary()`, collecting Docker/K8s/CI environment boolean flags, parent process name, install path prefix, and a random UUID — then exfiltrating as a URL-encoded JSON GET to a hardcoded canarytokens.com endpoint. The code explicitly self-labels this as an 'authorized-security-assessment canary' and provides an opt-out env var (`ECHOGEN_NO_CANARY=1`), strongly consistent with a supply-chain research or dependency-confusion probe rather than a weaponized stealer.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownechogenall (affected)—

References

vendor

Browse GCVE Records

3,142 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›