VDB
GCVE-110-OSM-2026-7857
GCVE-110-OSM-2026-7857
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration.
ENTRY
index.js (main: index.js)
EXFIL
- Environment Variable Exfiltration in commands/updateRelease.js: "process.env.GITHUB_REPOSITORY || 'joplin/plugins'; const apiBaseUrl = `https://a..."
- Environment Variable Exfiltration in dist/commands/updateRelease.js: "process.env.GITHUB_REPOSITORY || 'joplin/plugins'; const apiBaseUrl = `https://a..."
PAYLOAD FILES
commands/updateRelease.js (+ dist/commands/updateRelease.js)
INDICATORS (IOCs)
- urls: https://discourse.joplinapp.org/t/insert-referencing-notes-backlinks-plugin/13632
- domains: discourse.joplinapp.org
- sha256Hashes: 5676da6b9ad71fc5a9779d3bde13f17de5352344711e135f0db8c62c6dbb5696, 065285d06ea3c084e7f8f8c23583de8d70c4d586274a242c4c750f6faad8c7cb, 88daaf234a9b47e5644a8de6f830a801d12edbe41ea5364d994773e89eeafeef, df57930d1ab62d4297dad0bb1764888935fcbf6ca8c04e3a843e86a260735c51, b5dec8d00f19e34c4fe1dc0ed380b6743aa7debfd8f600ead0d6866ba21466f1
- payloadFileHash: 1535b71ee7f94c91f7d14839ed8cb3926f045377fc5049aa0f2db84fb2f93180
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @akshajrawat/plugin-repo-cli | all (affected) | — |
Aliases
Browse GCVE Records
75,797 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.