CVE-2026-77650
CRITICAL NVDCVSS Score
9.8
Severity
CRITICAL
Source
NVD
Published
Aug 21, 2026
Description
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.