Advisory Database
  • Advisories
  • Dependency Scanning
  1. cargo
  2. ›
  3. exploration
  4. ›
  5. GHSA-99j7-fhr2-xfj4

GHSA-99j7-fhr2-xfj4: `exploration` was removed from crates.io for malicious code

July 10, 2026

A method within the exploration crate attempted to download and execute a payload from a remote site.

The malicious crate had 1 version published on 2026-06-02, approximately 1 hour before removal, and had no evidence of actual usage. This crate had no dependencies on crates.io.

Rustsec to Kirill Boychenko from the Socket Threat Research Team for reporting this crate.

References

  • github.com/advisories/GHSA-99j7-fhr2-xfj4
  • rustsec.org/advisories/RUSTSEC-2026-0155.html

Code Behaviors & Features

Detect and mitigate GHSA-99j7-fhr2-xfj4 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions

Solution

Unfortunately, there is no solution available yet.

Weakness

  • CWE-506: Embedded Malicious Code

Source file

cargo/exploration/GHSA-99j7-fhr2-xfj4.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:16:45 +0000.