VDB
GCVE-110-OSM-2026-245
GCVE-110-OSM-2026-245
Advisory PublishedCVSS 9.6/10
Malicious Tessa Windows platform library version 2. Supply chain attack targeting Windows-based Tessa deployments with MSBuild-based code execution.
Exploits NuGet's MSBuild integration by placing malicious code in .targets files as inline tasks. When projects build, MSBuild automatically imports and executes these tasks, downloading .NET executables from throwaway GitHub repositories with embedded obfuscated command-line payloads.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | Stl.Plugins.Extensions.Net | all (affected), all (affected), all (affected), all (affected), all (affected), all (affected), all (affected), * (affected) | — |
| unknown | Tessa.Windows.V2 | all (affected) | — |
| unknown | Stl.CommandLine.Net | all (affected), * (affected), all (affected), * (affected), all (affected), * (affected) | — |
| unknown | Stl.Fusion.Ext.Contracts.Net | all (affected) | — |
| unknown | python-module-installer | 3.15.10 (affected) | — |
Aliases
References
Browse GCVE Records
74,147 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.