VDB
GCVE-110-OSM-2026-9110
GCVE-110-OSM-2026-9110
Advisory PublishedCVSS 5.4/10
The package itself is a simple, readable Recoil state observer React component with no malicious code in its entrypoint — the logic is entirely benign (snapshot logging and a local window.postMessage for devtools). However, two of its dependencies (eslint-config-prettier and eslint-plugin-prettier) are flagged as known malicious by OpenSourceMalware.com. These are dev dependencies commonly used in build tooling, and the flagging may be stale or erroneous given how widely used those packages legitimately are, but the OSM flags cannot be dismissed without further verification. The package itself poses no direct threat based on the code, but the dependency flags warrant investigation before clearing.
ENTRY
dist/index.cjs.js (main: dist/index.cjs.js)
ADDITIONAL FINDINGS
- Malicious Dependency Detected in package.json
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @g123jp/recoil-observer | 0.0.2 (affected) | — |
Browse GCVE Records
75,788 records in the GCVE database · Updated August 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.