Critical severity9.8NVD Advisory· Published Aug 21, 2026
CVE-2026-77650
CVE-2026-77650
Description
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
Affected products
1- Range: <0.1.9
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.