VDB

GCVE-110-OSM-2026-9237

GCVE-110-OSM-2026-9237
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 28, 2026
The package presents as a lightweight calendar/streak math utility but ships a single `index.mjs` file that is over 530 KB — extremely large for a 'dependency-free primitives' library. The deobfuscation step was skipped due to the file exceeding the size cap, so the actual content of that file cannot be assessed. A 530 KB minified/bundled file from a brand-new author with no source repository, published via a ProtonMail account with only two packages, warrants manual inspection before any trust is placed in it. The metadata signals (new account, single version, no repository) are individually weak but compound the anomaly of the oversized single-file bundle.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownstreak-core-liball (affected)

References

advisory
vendor

Browse GCVE Records

75,792 records in the GCVE database · Updated August 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›