VDB
GCVE-110-OSM-2026-9237
GCVE-110-OSM-2026-9237
Advisory PublishedCVSS 5.4/10
The package presents as a lightweight calendar/streak math utility but ships a single `index.mjs` file that is over 530 KB — extremely large for a 'dependency-free primitives' library. The deobfuscation step was skipped due to the file exceeding the size cap, so the actual content of that file cannot be assessed. A 530 KB minified/bundled file from a brand-new author with no source repository, published via a ProtonMail account with only two packages, warrants manual inspection before any trust is placed in it. The metadata signals (new account, single version, no repository) are individually weak but compound the anomaly of the oversized single-file bundle.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | streak-core-lib | all (affected) | — |
Aliases
Browse GCVE Records
75,792 records in the GCVE database · Updated August 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.