GHSA-99j7-fhr2-xfj4

Suggest an improvement
Source
https://github.com/advisories/GHSA-99j7-fhr2-xfj4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-99j7-fhr2-xfj4/GHSA-99j7-fhr2-xfj4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-99j7-fhr2-xfj4
Aliases
Published
2026-07-10T19:32:24Z
Modified
2026-07-11T06:26:40Z
Summary
`exploration` was removed from crates.io for malicious code
Details

A method within the exploration crate attempted to download and execute a payload from a remote site.

The malicious crate had 1 version published on 2026-06-02, approximately 1 hour before removal, and had no evidence of actual usage. This crate had no dependencies on crates.io.

Rustsec to Kirill Boychenko from the Socket Threat Research Team for reporting this crate.

Database specific
{
    "cwe_ids":  [
        "CWE-506"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-10T19:32:24Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

crates.io / exploration

Package

Name
exploration
View open source insights on deps.dev
Purl
pkg:cargo/exploration

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-99j7-fhr2-xfj4/GHSA-99j7-fhr2-xfj4.json"