VDB

GCVE-110-OSM-2026-13302

GCVE-110-OSM-2026-13302
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 5, 2026
This package is a self-described proof-of-concept RCE payload targeting Insomnia's plugin loader. The entrypoint index.js unconditionally executes at require() time: it spawns OS-native calculator processes via child_process.exec across all platforms, writes a proof file (INSOMNIA_RCE_PROOF.txt) to the user's Desktop outside the package directory, and serializes the entire process.env (including API keys, tokens, and secrets) to console output. The source comments explicitly describe the attack chain and state 'In a real attack this would be sent to an attacker-controlled server,' confirming adversarial intent. The publisher account is under 2 days old with only 2 packages published, both fitting the same attack theme. The OSV advisory MAL-2026-17561 is fully corroborated by the literal entrypoint code. ENTRY index.js (main: index.js) EXFIL - System Information Collection in index.js: "os.userInfo()" ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account PAYLOAD FILES index.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowninsomnia-plugin-api-lint-helperall (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›