VDB

GCVE-110-OSM-2026-1821

GCVE-110-OSM-2026-1821
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published April 11, 2026
Malicious VSCode tasks.json file that executes on the user device, if the repository is opened as trusted workspace. There are two types of Payload First one uses tasks.json second one is base64 encoded C2 in .env file that executes during the application runtime. Base64 encoded C2 is 2-27-bk-9-boss-api-copy-seven[.]vercel[.]app[/]api

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

References

Browse GCVE Records

74,355 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›