VDB

GCVE-110-OSM-2026-7857

GCVE-110-OSM-2026-7857
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 14, 2026
Malicious package detected. Behaviors: data exfiltration. ENTRY index.js (main: index.js) EXFIL - Environment Variable Exfiltration in commands/updateRelease.js: "process.env.GITHUB_REPOSITORY || 'joplin/plugins'; const apiBaseUrl = `https://a..." - Environment Variable Exfiltration in dist/commands/updateRelease.js: "process.env.GITHUB_REPOSITORY || 'joplin/plugins'; const apiBaseUrl = `https://a..." PAYLOAD FILES commands/updateRelease.js (+ dist/commands/updateRelease.js) INDICATORS (IOCs) - urls: https://discourse.joplinapp.org/t/insert-referencing-notes-backlinks-plugin/13632 - domains: discourse.joplinapp.org - sha256Hashes: 5676da6b9ad71fc5a9779d3bde13f17de5352344711e135f0db8c62c6dbb5696, 065285d06ea3c084e7f8f8c23583de8d70c4d586274a242c4c750f6faad8c7cb, 88daaf234a9b47e5644a8de6f830a801d12edbe41ea5364d994773e89eeafeef, df57930d1ab62d4297dad0bb1764888935fcbf6ca8c04e3a843e86a260735c51, b5dec8d00f19e34c4fe1dc0ed380b6743aa7debfd8f600ead0d6866ba21466f1 - payloadFileHash: 1535b71ee7f94c91f7d14839ed8cb3926f045377fc5049aa0f2db84fb2f93180

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@akshajrawat/plugin-repo-cliall (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›