Remote Code Execution Vulnerability in use-context-selector by Dai Shi
CVE-2026-48158

9.3CRITICAL

Key Information:

Vendor

Dai-shi

Vendor
CVE Published:
10 August 2026

What is CVE-2026-48158?

The use-context-selector package from Dai Shi has been compromised through malicious commits that were active between May 18 and May 19, 2026. During this time, the package was manipulated to execute arbitrary code on developer machines upon running npm install. The malicious code, which was cleverly embedded in a script added to the post-install process, fetched a payload from an attacker-controlled endpoint and disabled TLS verification, allowing full compromise of any system components accessible from a Node process with the user's permissions. Though the harmful commits have been removed, developers who cloned or forked the affected repository should consider any installations as potentially compromised, prompting the need for credential rotation, account activity audits, and cleaning of local repositories.

Affected Version(s)

use-context-selector >= 9d8481a513b7b0d1c0941b220c69b25de748641b, <= 6f2dae054ca014068bdbbb4db96006424d674124

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.