VDB

GCVE-110-OSM-2026-8166

GCVE-110-OSM-2026-8166
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 16, 2026
Malicious package detected. Behaviors: data exfiltration. ENTRY qwen_asr/cli/demo.py (console-script: qwen-asr-demo=qwen_asr.cli.demo:main) DESTINATION - custom-c2: https://huggingface.co/collections/Qwen/qwen3-asr (primary, plaintext) in PKG-INFO - custom-c2: https://modelscope.cn/collections/Qwen/Qwen3-ASR (plaintext) in PKG-INFO - custom-c2: https://qwen.ai/blog?id=qwen3asr (plaintext) in PKG-INFO - custom-c2: https://arxiv.org/abs/2601.21337 (plaintext) in PKG-INFO - custom-c2: https://huggingface.co/spaces/Qwen/Qwen3-ASR (plaintext) in PKG-INFO - custom-c2: https://modelscope.cn/studios/Qwen/Qwen3-ASR (plaintext) in PKG-INFO - custom-c2: https://huggingface.co/Qwen/Qwen3-ASR-1.7B-hf (plaintext) in PKG-INFO - custom-c2: https://huggingface.co/Qwen/Qwen3-ASR-0.6B-hf (plaintext) in PKG-INFO (+21 more) EXFIL - Data Encoding for Exfiltration in qwen_asr/cli/demo.py: "base64.b64encode(" - Data Encoding for Exfiltration in qwen_asr/cli/demo_streaming.py: "encodeURIComponent(sessionId" - Network Request in PKG-INFO: "requests.post(" - Network Request in qwen_asr/inference/utils.py: "urllib.request.urlopen(" PAYLOAD FILES qwen_asr/cli/demo_streaming.py (+ qwen_asr/cli/demo.py) INDICATORS (IOCs) - urls: https://huggingface.co/papers/2305.13245 - payloadFileHash: 9a5ac7ad64e93c06dce06dc9a6808585dd8af3b382952864f0470536f9245bff

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownqwen-asr-pvtall (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›