@ai-vertical/ai-agent@1.0.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC
OSV ID
MAL-2026-14070
Ecosystem
npm
Summary
On require/import, index.js fetches a hardcoded GitHub Gist (gist.github.com/aiverticalsolutions/7676451d2f972137d2482c4a8937a77a) via the api.github.com gists endpoint and passes the returned file contents directly to eval(). The gist is author-controlled and mutable, so whatever code the maintainer places there executes with the privileges of any process that loads this package. The package ships with empty description and empty author metadata and contains no other functionality — the remote-eval loader is the entire module.
Source: amazon-inspector (f3daa0f3fabdeebe3db0146233d623d65ae16aea601e54fd6519a160db5af8ee)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.