CVE-2026-77650CWE-506
CVE-2026-77650
Critical · published August 21, 2026
What it is
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
The record
Technical detail
- CVSS v3.1
- 9.8 · CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00434 · 36.4th percentile
- Weakness
- CWE-506 · Embedded Malicious Code
- Published
- 2026-08-21T05:17Z
References (5)
EPSS history
Timeline