VDB
GCVE-110-OSM-2026-4248
GCVE-110-OSM-2026-4248
Advisory PublishedCVSS 9.6/10
[osmalyze-auto] Malicious package detected. Behaviors: data exfiltration, code execution, network activity.
[osmalyze-auto] Exfil: https://xyz.oast.me (oast, recovery: plaintext in PKG-INFO)
Payload: src/commonhuman_payloads/xss/advanced.py
Secondary files: PKG-INFO, src/commonhuman_payloads/sqli/advanced.py
Key findings:
- OAST/Interactsh Exfiltration in PKG-INFO: ".oast.me"
- Sensitive File Access in src/commonhuman_payloads/sqli/advanced.py: "'/etc/passwd'"
- Base64 Decoded Eval in src/commonhuman_payloads/xss/advanced.py: "eval(atob("
- Data Encoding for Exfiltration in src/commonhuman_payloads/encoders/transforms.py: "urllib.parse.quote("
- Dynamic Code Execution in src/commonhuman_payloads/xss/advanced.py: "eval(name)"
IOCs:
- ipv6: 1::
- urls: https://xyz.oast.me, http://{callback, http://attacker.example/?, http://attacker.example/\, http://attacker.example/?d= (+1 more)
- domains: xyz.oast.me, sucuri.net, prompt.ml
- emails: trusted.example%2f@attacker.example
- oastEndpoints: https://xyz.oast.me
- payloadFileHash: 19b17b1b4c3d6ebc445ddc595b88a2ccaac4e9d573a9dc63fd195f78d2d98c29
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | commonhuman-payloads | 0.1.0 (affected) | — |
Browse GCVE Records
74,557 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.