VDB

GCVE-110-OSM-2026-8374

GCVE-110-OSM-2026-8374
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 18, 2026
Malicious package detected. Behaviors: code execution. ENTRY setup.py (install-hook: install/develop/build override present) - setup.py Code Execution in setup.py ADDITIONAL FINDINGS - Shell Command Execution in setup.py: "subprocess.run(" - Setup.py Command Override in setup.py: "cmdclass={'install'" PAYLOAD FILES setup.py INDICATORS (IOCs) - urls: https://capsule-render.vercel.app/api?type=waving&color=0:E3342F, https://readme-typing-svg.demolab.com?font=Fira+Code&weight=600&size=20&pause=800&color=E3342F&center=true&vCenter=true&width=650&lines=OAuth+2.0+%E2%80%94+No+Cookie+Required;Typed+Models+for+Every+API+Response;Async+%2B+Sync+Clients+Built+In;SQLite+Database+Layer+Included;Open+Cloud+%2B+DataStore+Support;Real-time+Event+System;Marketplace+%26+RAP+Tracking+Tools;Interactive+Terminal+REPL;Production+Ready+%F0%9F%9A%80, https://roboat.pro, http://proxy:8080, https://capsule-render.vercel.app/api?type=waving&color=0:991B1B - domains: capsule-render.vercel.app, readme-typing-svg.demolab.com, roboat.pro - payloadFileHash: 9184bebdc6f1db12958f37d521105d721297a57e5fb273c5fa1fbaac24a33746

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownrblx-httpall (affected)

References

vendor
advisory

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›