VDB
GCVE-110-OSM-2026-8166
GCVE-110-OSM-2026-8166
Advisory PublishedCVSS 8.8/10
Malicious package detected. Behaviors: data exfiltration.
ENTRY
qwen_asr/cli/demo.py (console-script: qwen-asr-demo=qwen_asr.cli.demo:main)
DESTINATION
- custom-c2: https://huggingface.co/collections/Qwen/qwen3-asr (primary, plaintext) in PKG-INFO
- custom-c2: https://modelscope.cn/collections/Qwen/Qwen3-ASR (plaintext) in PKG-INFO
- custom-c2: https://qwen.ai/blog?id=qwen3asr (plaintext) in PKG-INFO
- custom-c2: https://arxiv.org/abs/2601.21337 (plaintext) in PKG-INFO
- custom-c2: https://huggingface.co/spaces/Qwen/Qwen3-ASR (plaintext) in PKG-INFO
- custom-c2: https://modelscope.cn/studios/Qwen/Qwen3-ASR (plaintext) in PKG-INFO
- custom-c2: https://huggingface.co/Qwen/Qwen3-ASR-1.7B-hf (plaintext) in PKG-INFO
- custom-c2: https://huggingface.co/Qwen/Qwen3-ASR-0.6B-hf (plaintext) in PKG-INFO
(+21 more)
EXFIL
- Data Encoding for Exfiltration in qwen_asr/cli/demo.py: "base64.b64encode("
- Data Encoding for Exfiltration in qwen_asr/cli/demo_streaming.py: "encodeURIComponent(sessionId"
- Network Request in PKG-INFO: "requests.post("
- Network Request in qwen_asr/inference/utils.py: "urllib.request.urlopen("
PAYLOAD FILES
qwen_asr/cli/demo_streaming.py (+ qwen_asr/cli/demo.py)
INDICATORS (IOCs)
- urls: https://huggingface.co/papers/2305.13245
- payloadFileHash: 9a5ac7ad64e93c06dce06dc9a6808585dd8af3b382952864f0470536f9245bff
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | qwen-asr-pvt | all (affected) | — |
Aliases
Browse GCVE Records
75,797 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.