The append-only-vec crate 0.1.9 for Rust has a critical vulnerability (CVSS score of 9.8) due to a rogue dependency that registers with a command-and-control server to offer arbitrary code execution when compiling a project that uses the crate. This supply chain attack can trigger execution of malicious code. Rust developers and users who utilize this crate should review and update their projects immediat [truncated]
The internment crate 0.8.7 for Rust contains a critical vulnerability (CVE-2026-77649) that allows for arbitrary code execution when compiling a project that uses the crate. This is due to a rogue dependency that registers with a command-and-control server. The vulnerability has a CVSS score of 9.8, indicating a high severity. Developers using this crate in their Rust projects and organizations relying on [truncated]