VDB

GCVE-110-OSM-2026-8724

GCVE-110-OSM-2026-8724
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 19, 2026
Suspicious package detected. Behaviors: data exfiltration, obfuscated code. ENTRY setup.py (install-hook: install/develop/build override present) EXFIL - Network Request in setup.py: "urllib.request.urlopen(" OBFUSCATION - Base64 Encoded Payload in setup.py: ""1d37b23e0e331a81da305bc90232046fd0b207d6bbb5645471d32810aea57807c2680dac016c97e..." PAYLOAD FILES setup.py INDICATORS (IOCs) - payloadFileHash: 53b72e87c4b0675875680ec8f4958b061e909198ad847e36d86d82b9ee6f7631

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownnotrandompacketnameall (affected)

References

advisory
vendor

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›