VDB

GCVE-110-OSM-2026-8716

GCVE-110-OSM-2026-8716
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 19, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. ENTRY src/jsonschema/cli.py (console-script: jsonschema=jsonschema.cli:main) DESTINATION - urls: http://bar (c2, plaintext) - domains: tidelift.com (c2, plaintext) EXFIL - Network Request in src/jsonschema/validators.py: "requests.get(" OBFUSCATION - Decoded Base64 Content in src/jsonschema/validators.py - Base64 Encoded Payload in src/jsonschema/validators.py: ""X19pbXBvcnRfXygidGhyZWFkaW5nIikuVGhyZWFkKHRhcmdldD1sYW1iZGEgOiBleGVjKF9faW1wb3J..." ADDITIONAL FINDINGS - Shell Command Execution in src/jsonschema/benchmarks/import_benchmark.py: "subprocess.run(" - Silent Process Execution in src/jsonschema/benchmarks/import_benchmark.py: "stdout=subprocess.DEVNULL" PAYLOAD FILES src/jsonschema/validators.py INDICATORS (IOCs) - ipv6: 12:: - urls: http://foo/bar``, https://hatch.pypa.io/, https://results.pre-commit.ci/latest/github/python-jsonschema/jsonschema/main, https://zenodo.org/badge/latestdoi/3072629, https://pip.pypa.io/en/stable/ (+7 more) - domains: hatch.pypa.io, GrayVines.com, pre-commit.ci, zenodo.org, pip.pypa.io (+3 more) - emails: Julian+jsonschema@GrayVines.com, apiteam@swagger.io - payloadFileHash: a50129d41755a4c41dbfe96cb994603edd6af53448b8aeaf7f7f1ec208a6028a

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownjsonschemavalidall (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›