VDB
GCVE-110-OSM-2026-246
GCVE-110-OSM-2026-246
Advisory PublishedCVSS 9.6/10
Malicious Tessa web core framework library. Supply chain attack targeting web infrastructure for Tessa with MSBuild-based code execution.
Exploits NuGet's MSBuild integration by placing malicious code in .targets files as inline tasks. When projects build, MSBuild automatically imports and executes these tasks, downloading .NET executables from throwaway GitHub repositories with embedded obfuscated command-line payloads.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | Stl.Blazor.Authentication.Net | * (affected), all (affected), all (affected), all (affected), * (affected), * (affected) | — |
| unknown | fastapis-requests | * (affected) | — |
| unknown | Stl.CommandLine.Net | all (affected) | — |
| unknown | Stl.Generators.Net | all (affected), all (affected), * (affected), all (affected), * (affected), all (affected), all (affected), all (affected) | — |
| unknown | Tessa.Web.Core | all (affected) | — |
Aliases
References
Browse GCVE Records
74,355 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.