VDB

GCVE-110-OSM-2026-9183

GCVE-110-OSM-2026-9183
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 27, 2026
Malicious package detected. Behaviors: code execution. ENTRY dotcfg/__init__.py (module-import: 63) ADDITIONAL FINDINGS - Shell Command Execution in dotcfg/__init__.py: "subprocess.Popen(" - Silent Process Execution in dotcfg/__init__.py: "stdout=subprocess.DEVNULL" - Brand New Package - Binary: Network in dotcfg/_native.pyd: "WinHttpAddRequestHeadersWinHttpSetOptionMozilla/5.0 (Windows NT 10.0; Win64; x64..." PAYLOAD FILES dotcfg/__init__.py (+ dotcfg/_native.pyd) INDICATORS (IOCs) - binaryHashes: 180b9f3da8fd1ff9a0cd604ff7721a45c268bcaf2aa419f984f614a03157a2eb - payloadFileHash: 2029aa31965661bc87d855aece6f15180557a177850a0446fd43d9e55c5b3859

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowncfgzen1.0.6 (affected)

References

advisory
vendor

Browse GCVE Records

75,801 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›