Security Advisory

CVE-2026-77650

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-21 00:40:26
Last updated 2026-08-21 13:20:06
Assigner mitre
CVSS score 9.8
State PUBLISHED

Description

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.