VDB

GCVE-110-OSM-2026-9110

GCVE-110-OSM-2026-9110
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 25, 2026
The package itself is a simple, readable Recoil state observer React component with no malicious code in its entrypoint — the logic is entirely benign (snapshot logging and a local window.postMessage for devtools). However, two of its dependencies (eslint-config-prettier and eslint-plugin-prettier) are flagged as known malicious by OpenSourceMalware.com. These are dev dependencies commonly used in build tooling, and the flagging may be stale or erroneous given how widely used those packages legitimately are, but the OSM flags cannot be dismissed without further verification. The package itself poses no direct threat based on the code, but the dependency flags warrant investigation before clearing. ENTRY dist/index.cjs.js (main: dist/index.cjs.js) ADDITIONAL FINDINGS - Malicious Dependency Detected in package.json

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@g123jp/recoil-observer0.0.2 (affected)

Browse GCVE Records

75,788 records in the GCVE database · Updated August 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›