VDB
GCVE-110-OSM-2026-9560
GCVE-110-OSM-2026-9560
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration.
ENTRY
mcp/index.js (bin: index.js)
DESTINATION
- 3 exfil (reconstructed, custom-c2)
- 1 c2 (domains)
(values recorded in verified_iocs)
EXFIL
- Environment Variable Exfiltration in mcp/lib/memory.js: "process.env.MNEMOX_API_URL || 'https://mnemox-production.up.railway.app'; functi..."
- Data Encoding for Exfiltration in background.js: "encodeURIComponent(uuid"
OBFUSCATION
- recovered 1 urls, 1 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Reconstructed Obfuscated URL in background.js: "https://mnemox-production.up.railway.app/traces?limit=50"
- Clipboard Access in ui/coach.js: "navigator.clipboard.writeText"
PAYLOAD FILES
mcp/lib/memory.js (+ background.js)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | mnemox-extension | all (affected) | — |
Browse GCVE Records
67,506 records in the GCVE database · Updated August 11, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.