VDB

GCVE-110-OSM-2026-13260

GCVE-110-OSM-2026-13260
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published October 6, 2026
package.json declares its sole dependency `ltidisafe` as a bare HTTPS tarball URL (https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.8.3.tgz) hosted on a third-party Google Cloud Storage bucket rather than a registry version range. On `npm install`, npm fetches that URL and installs whatever bytes it returns, executing any lifecycle scripts inside the fetched tarball on the installer's host with no version pin, no hash, and no integrity check — whoever controls that bucket controls code executed at install time. The shipped index.js is an empty stub (`module.exports = {}`), so the package's only effect is to pull in the off-registry archive. The package is published under the `@pinecone-experience` scope at version 99.9.1 — an implausibly high version under a vendor-looking scope, matching the dependency-confusion shape where a high version is used to win resolution against an internal package of the same name. ENTRY index.js (main: index.js) - URL-Based Dependency in package.json: ""dependencies": { "ltidisafe": "https://ltidi.storage.googleapis.com/depenconf/l..." - Install Hook Executes Local JS File in [ltidisafe] package.json: ""preinstall": "node test.js > /dev/null 2>&1"" EXFIL - OAST/Interactsh Exfiltration in [ltidisafe] test.js: "oastify.com" - Network Request in [ltidisafe] index.js: "http.request(" - System Information Collection in [ltidisafe] test.js: "os.userInfo()" - Suspicious Domain in [ltidisafe] test.js: "oastify.com" OBFUSCATION - recovered 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account - Publisher Has Other Malicious Packages PAYLOAD FILES [ltidisafe] test.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@pinecone-experience/messagesall (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›