criticalVulnerability

GHSA-99j7-fhr2-xfj4

A method within the `exploration` crate attempted to download and execute a payload from a remote site. The malicious crate had 1 version published on 2026-06-02, approximately 1 hour before removal, and had no evidence of actual usage. This crate had no dependencies on crates.io. Rustsec to Kirill Boychenko from the [Socket Threat Research Team](https://socket.dev/) for reporting this crate.

Properties

ghsa_id
GHSA-99j7-fhr2-xfj4
severity
critical
summary
`exploration` was removed from crates.io for malicious code
cve_id
GHSA-99j7-fhr2-xfj4
is_ghsa_only
true
ghsa_published
2026-07-10T19:32:24Z
source_url
https://github.com/advisories/GHSA-99j7-fhr2-xfj4
ghsa_updated
2026-07-10T19:32:24Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Embedded Malicious Code

VULNERABLE_TO (1)

[Software]rust/exploration

AFFECTS (1)

[Software]rust/exploration

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-99j7-fhr2-xfj4 — Ninja Signal Threat Intelligence | Ninja Signal