CVE-2026-77651
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
| CWE | CWE-506 |
| Vendor | droundy |
| Product | arrayref |
| Published | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for droundy arrayref
Be the first to know when new critical vulnerabilities affecting droundy arrayref are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
droundy / arrayref
0.3.10
References
blog.rust-lang.org: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref github.com: https://github.com/rustsec/advisory-db/issues/3161 stepsecurity.io: https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack safedep.io: https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/ rustsec.org: https://rustsec.org/advisories/RUSTSEC-2026-0260.html