{"id":"GHSA-99j7-fhr2-xfj4","summary":"`exploration` was removed from crates.io for malicious code","details":"A method within the `exploration` crate attempted to download and execute a payload from a remote site.\n\nThe malicious crate had 1 version published on 2026-06-02, approximately 1 hour before removal, and had no evidence of actual usage. This crate had no dependencies on crates.io.\n\nRustsec to Kirill Boychenko from the [Socket Threat Research Team](https://socket.dev/) for reporting this crate.","aliases":["RUSTSEC-2026-0155"],"modified":"2026-07-11T06:26:40.907706714Z","published":"2026-07-10T19:32:24Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-506"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-07-10T19:32:24Z"},"references":[{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0155.html"}],"affected":[{"package":{"name":"exploration","ecosystem":"crates.io","purl":"pkg:cargo/exploration"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-99j7-fhr2-xfj4/GHSA-99j7-fhr2-xfj4.json"}}],"schema_version":"1.9.0"}