VDB
GCVE-110-OSM-2026-3215
GCVE-110-OSM-2026-3215
Advisory PublishedCVSS 8.8/10
Suspected dependency confusion attack. Behaviors: data exfiltration.
Payload: src/boba/interaction/session.py
Secondary files: src/boba/payloads/ai.py, src/boba/core/subprocess.py
Key findings:
- Silent Process Execution in src/boba/core/subprocess.py: "subprocess.DEVNULL"
- Data Encoding for Exfiltration in src/boba/interaction/session.py: "base64.b64encode("
IOCs:
- ipv4: 93.184.216.34, 5.6.7.8
- ipv6: 1::
- urls: http://www.apache.org/licenses/, http://www.apache.org/licenses/LICENSE-2.0, https://app.acme.com/search, https://app.acme.com/admin, https://acme.com/api/ (+45 more)
- domains: kaminocorp.com, gofastmcp.com, www.apache.org, acme.com, crt.sh (+20 more)
- emails: attacker@evil.com, dev@acme.com, ci@acme.com
- awsAccessKeys: AKIAIOSFODNN7EXAMPLE, AKIA1234567890ABCDEF
- githubTokens: ghp_abcdefghijklmnopqrstuvwxyz1234567890
- oastEndpoints: http://abc123.oast.fun
- payloadFileHash: 7cf352c00de452b2b46c76560a1d021032dd1adf9442bb598625e5d2543c02b6
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | boba-hunter | all (affected) | — |
Browse GCVE Records
74,108 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.