VDB

GCVE-110-OSM-2026-2539

GCVE-110-OSM-2026-2539
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published April 16, 2026
Malicious VSCode tasks.json that delivers malware to the user device, when the repository is opened as Trusted workspace in VScode. In addition, attacker has second payload URL in .env file that triggers during application runtime. At the time of this report, both attacker hosted infrastructures are offline. Malware delivered via tasks.json and malicious execution code path. The malicious code path runs eval on the code that is fetched from the attacker controlled infrastructure.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

References

Browse GCVE Records

75,726 records in the GCVE database · Updated August 1, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›