Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
MSC-2026-11585
Published:September 05, 2026
Updated:September 05, 2026
Package beacons the local username and hostname to an out-of-band Interactsh collector. In the wheel the beacon runs at import time from metricboxlite/__init__.py; in the sdist it also runs during pip build from setup.py, before setup() is called, so installing from source leaks without any import. Version 1.0 shipped the same beacon code pointed at an unresolvable .invalid endpoint; version 2.0 changed only the version string, the summary and the endpoint, activating it. 879 bytes were observed leaving the analysis sandbox to the collector.
Do you need more information?
Contact Us
CVSS v4
Base Score:
8.8
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
HIGH
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
8.6
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
HIGH
Exploit Maturity
HIGH
Weakness Type (CWE)
Embedded Malicious Code