CVE-2026-77651CWE-506

CVE-2026-77651

Critical · published August 21, 2026

CVSS v3.1
9.8
EPSS
0%
Percentile
37.9
In the wild
Unconfirmed
What it is

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00453 · 37.9th percentile
Weakness
CWE-506 · Embedded Malicious Code
Published
2026-08-21T05:17Z
References (5)
EPSS history
Timeline
  • 21 AUG 00:41Z
    The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that…
    cvelistv5