VDB
GCVE-110-OSM-2026-13302
GCVE-110-OSM-2026-13302
Advisory PublishedCVSS 8.8/10
This package is a self-described proof-of-concept RCE payload targeting Insomnia's plugin loader. The entrypoint index.js unconditionally executes at require() time: it spawns OS-native calculator processes via child_process.exec across all platforms, writes a proof file (INSOMNIA_RCE_PROOF.txt) to the user's Desktop outside the package directory, and serializes the entire process.env (including API keys, tokens, and secrets) to console output. The source comments explicitly describe the attack chain and state 'In a real attack this would be sent to an attacker-controlled server,' confirming adversarial intent. The publisher account is under 2 days old with only 2 packages published, both fitting the same attack theme. The OSV advisory MAL-2026-17561 is fully corroborated by the literal entrypoint code.
ENTRY
index.js (main: index.js)
EXFIL
- System Information Collection in index.js: "os.userInfo()"
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
PAYLOAD FILES
index.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | insomnia-plugin-api-lint-helper | all (affected) | — |
Aliases
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.