VDB
GCVE-110-OSM-2026-13325
GCVE-110-OSM-2026-13325
Advisory PublishedCVSS 5.4/10
This package is a purpose-built remote-code-execution loader: on import it fetches arbitrary Python source from a caller-supplied URL, compiles it, and executes it in-process via exec(compile(src, ...)). The design is structurally identical to a dropper — the only thing separating 'framework' from 'malware' is what the server eventually serves.
To that last point, currently this package is defanged and does not call a payload from a real, functioning url. However, taking this behaviour as a whole, we are flagging this as a low, because the authors package description does not match what the code is actually doing. Add to that the fact that if the author adds a malicious url to this package it suddenly becomes a much more immediate threat.
ENTRY
qwen3ttsui/__init__.py (module-import: 67)
DESTINATION
- 1 c2 (urls)
(values recorded in verified_iocs)
EXFIL
- Network Request in qwen3ttsui/__init__.py: "urllib.request.urlopen("
ADDITIONAL FINDINGS
- Dynamic Code Execution in qwen3ttsui/__init__.py: "compile(src, mod.__file__, "exec")"
PAYLOAD FILES
qwen3ttsui/__init__.py
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | qwen3ttsui | all (affected) | — |
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.