Code Execution Vulnerability in Internment Crate for Rust
CVE-2026-77649

9.8CRITICAL

Key Information:

Vendor

Droundy

Vendor
CVE Published:
21 August 2026

What is CVE-2026-77649?

The Internment crate version 0.8.7 for Rust contains a vulnerability that can allow the execution of malicious code during project compilation. This occurs due to a problematic dependency that connects to a command-and-control server, allowing for arbitrary code execution. Developers using this crate are urged to review their dependencies and ensure they are not utilizing the affected version, as it poses significant risks to application integrity and security.

Affected Version(s)

internment 0.8.7

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.