VDB

GCVE-110-OSM-2026-3215

GCVE-110-OSM-2026-3215
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published April 25, 2026
Suspected dependency confusion attack. Behaviors: data exfiltration. Payload: src/boba/interaction/session.py Secondary files: src/boba/payloads/ai.py, src/boba/core/subprocess.py Key findings: - Silent Process Execution in src/boba/core/subprocess.py: "subprocess.DEVNULL" - Data Encoding for Exfiltration in src/boba/interaction/session.py: "base64.b64encode(" IOCs: - ipv4: 93.184.216.34, 5.6.7.8 - ipv6: 1:: - urls: http://www.apache.org/licenses/, http://www.apache.org/licenses/LICENSE-2.0, https://app.acme.com/search, https://app.acme.com/admin, https://acme.com/api/ (+45 more) - domains: kaminocorp.com, gofastmcp.com, www.apache.org, acme.com, crt.sh (+20 more) - emails: attacker@evil.com, dev@acme.com, ci@acme.com - awsAccessKeys: AKIAIOSFODNN7EXAMPLE, AKIA1234567890ABCDEF - githubTokens: ghp_abcdefghijklmnopqrstuvwxyz1234567890 - oastEndpoints: http://abc123.oast.fun - payloadFileHash: 7cf352c00de452b2b46c76560a1d021032dd1adf9442bb598625e5d2543c02b6

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownboba-hunterall (affected)

References

vendor

Browse GCVE Records

74,108 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›