VDB

GCVE-110-OSM-2026-3026

GCVE-110-OSM-2026-3026
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published April 22, 2026
Malicious vscode tasks.json file that delivers malware to user device, when the repository is opened as trusted workspace. There are two payload delivery methods first one is visual studio code tasks.json Second one is base64 encoded value in the .env file that exfiltrates environment variables accessible during run time to y-nu-roan[.]vercel[.]app[/]api

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown* (affected)

References

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›