VDB
GCVE-110-OSM-2026-8373
GCVE-110-OSM-2026-8373
Advisory PublishedCVSS 8.8/10
Malicious package detected. Behaviors: code execution.
ENTRY
setup.py (install-hook: install/develop/build override present)
- setup.py Code Execution in setup.py
ADDITIONAL FINDINGS
- Shell Command Execution in setup.py: "subprocess.run("
- Setup.py Command Override in setup.py: "cmdclass={'install'"
PAYLOAD FILES
setup.py
INDICATORS (IOCs)
- urls: https://capsule-render.vercel.app/api?type=waving&color=0:E3342F, https://readme-typing-svg.demolab.com?font=Fira+Code&weight=600&size=20&pause=800&color=E3342F¢er=true&vCenter=true&width=650&lines=OAuth+2.0+%E2%80%94+No+Cookie+Required;Typed+Models+for+Every+API+Response;Async+%2B+Sync+Clients+Built+In;SQLite+Database+Layer+Included;Open+Cloud+%2B+DataStore+Support;Real-time+Event+System;Marketplace+%26+RAP+Tracking+Tools;Interactive+Terminal+REPL;Production+Ready+%F0%9F%9A%80, https://roboat.pro, http://proxy:8080, https://capsule-render.vercel.app/api?type=waving&color=0:991B1B
- domains: capsule-render.vercel.app, readme-typing-svg.demolab.com, roboat.pro
- payloadFileHash: dad887d97cf811d5374282455365bd3f4f26bd8b9d3042120711bb5be39b25f7
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | robase-dnb | all (affected) | — |
Aliases
Browse GCVE Records
75,788 records in the GCVE database · Updated August 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.