VDB
GCVE-110-OSM-2026-13406
GCVE-110-OSM-2026-13406
Advisory PublishedCVSS 8.8/10
src/package/install.js:20 hardcodes a raw-IP download source ('http://49.232.144.199/downloads') over plain HTTP, and the postinstall hook downloads a native binary, chmods it executable (install.js:530) and executes it via spawnSync (install.js:468,535). Checksum enforcement is trivially bypassable (install.js:399 disables it when VERSION != PKG.version via VLINK_VERSION), so the install hook effectively runs attacker-controlled second-stage code on every install.
## Static analysis (vigil)
Verdict `REVIEW`, score 27/100. Critical/high findings:
- [high] SC-035 Raw IP address request — `package/install.js:20`
- [high] MANIFEST-007 Install script executes local file — `package/package.json:1`
## Package metadata
- Publisher: unknown
- Published: 2026-10-08T06:39:01.742Z
- Install hooks: postinstall=node install.js
- SHA-256 (tarball): `ae05b00cf71914e39abea18f35b7549ed71274de7338d6b7f1c626297c4b0a6d`
## IOCs (defanged)
- 49[.]232[.]144[.]199
- gitee[.]com
- hxxps://49[.]232[.]144[.]199/downloads
- hxxps://gitee[.]com/api/v5/repos/ted-team/tedbrain
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @tedbrain/vlink | 0.1.76 (affected) | — |
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.