VDB

GCVE-110-OSM-2026-4248

GCVE-110-OSM-2026-4248
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published May 14, 2026
[osmalyze-auto] Malicious package detected. Behaviors: data exfiltration, code execution, network activity. [osmalyze-auto] Exfil: https://xyz.oast.me (oast, recovery: plaintext in PKG-INFO) Payload: src/commonhuman_payloads/xss/advanced.py Secondary files: PKG-INFO, src/commonhuman_payloads/sqli/advanced.py Key findings: - OAST/Interactsh Exfiltration in PKG-INFO: ".oast.me" - Sensitive File Access in src/commonhuman_payloads/sqli/advanced.py: "'/etc/passwd'" - Base64 Decoded Eval in src/commonhuman_payloads/xss/advanced.py: "eval(atob(" - Data Encoding for Exfiltration in src/commonhuman_payloads/encoders/transforms.py: "urllib.parse.quote(" - Dynamic Code Execution in src/commonhuman_payloads/xss/advanced.py: "eval(name)" IOCs: - ipv6: 1:: - urls: https://xyz.oast.me, http://{callback, http://attacker.example/?, http://attacker.example/\, http://attacker.example/?d= (+1 more) - domains: xyz.oast.me, sucuri.net, prompt.ml - emails: trusted.example%2f@attacker.example - oastEndpoints: https://xyz.oast.me - payloadFileHash: 19b17b1b4c3d6ebc445ddc595b88a2ccaac4e9d573a9dc63fd195f78d2d98c29

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowncommonhuman-payloads0.1.0 (affected)

Browse GCVE Records

74,557 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›