VDB

GCVE-110-PUB-2026-000649

GCVE-110-PUB-2026-000649
Advisory Published
Vulnetix · Advisory published September 5, 2026
The pub.dev package `maat` (version 0.1.2) was flagged as malicious by automated package analysis (1 corroborating detection(s)). Installing it may execute attacker-controlled code via Dart build hooks (hook/build.dart) or bundled Dart sources run with `dart run`. Verdict path: evidence — for ownership-only paths (owner-known-bad / multi-identity) the change of ownership is a compounding indicator the engine correlated with other signals, not standalone proof. This verdict is produced by static analysis and is subject to human review.

Weaknesses (CWE)

CWE-506Embedded Malicious CodeCWE-522Insufficiently Protected Credentials

Affected Products

VendorProductVersionsPlatforms
pubdevmaat0.1.2 (affected), 0.1.2 (affected), 0.1.2 (affected), 0.1.2 (affected), 0.1.2 (affected), 0.1.2 (affected), 0.1.2 (affected), 0.1.2 (affected)

References

advisory
web

Browse GCVE Records

540 records in the GCVE database · Updated September 8, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›