Back to overview

CVE-2026-34841

CRITICAL
9.8
CVSS 3.1
Description
Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran npm install between 00:21 UTC and ~03:30 UTC on March 31, 2026 may have been impacted. Upgrade to 3.2.1

Metadata

CVE ID
CVE-2026-34841
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-03-30 20:52 UTC
Published
2026-04-06 16:08 UTC
Last updated
2026-04-08 03:55 UTC
Primary CWE
CWE-494
CWE-494: Download of Code Without Integrity Check
Vendor / Product
usebruno / bruno
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
usebruno bruno < 3.2.1
Weakness (CWE)
CWESourceDescription
CWE-494 cna CWE-494: Download of Code Without Integrity Check
CWE-506 cna CWE-506: Embedded Malicious Code
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References (4)
Back to overview