VDB

GCVE-110-OSM-2026-13406

GCVE-110-OSM-2026-13406
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 8, 2026
src/package/install.js:20 hardcodes a raw-IP download source ('http://49.232.144.199/downloads') over plain HTTP, and the postinstall hook downloads a native binary, chmods it executable (install.js:530) and executes it via spawnSync (install.js:468,535). Checksum enforcement is trivially bypassable (install.js:399 disables it when VERSION != PKG.version via VLINK_VERSION), so the install hook effectively runs attacker-controlled second-stage code on every install. ## Static analysis (vigil) Verdict `REVIEW`, score 27/100. Critical/high findings: - [high] SC-035 Raw IP address request — `package/install.js:20` - [high] MANIFEST-007 Install script executes local file — `package/package.json:1` ## Package metadata - Publisher: unknown - Published: 2026-10-08T06:39:01.742Z - Install hooks: postinstall=node install.js - SHA-256 (tarball): `ae05b00cf71914e39abea18f35b7549ed71274de7338d6b7f1c626297c4b0a6d` ## IOCs (defanged) - 49[.]232[.]144[.]199 - gitee[.]com - hxxps://49[.]232[.]144[.]199/downloads - hxxps://gitee[.]com/api/v5/repos/ted-team/tedbrain

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@tedbrain/vlink0.1.76 (affected)—

References

vendor

Browse GCVE Records

3,328 records in the GCVE database · Updated October 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›