Ad

CVE-2026-34841

CRITICAL CVSS 3.1: 9.8 EPSS 0.03%
Updated Apr 07, 2026
Bruno
Parameter Value
CVSS 9.8 (CRITICAL)
Fixed In 3.2.1
Type CWE-506, CWE-494
Vendor Bruno
Public PoC No

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran npm install between 00:21 UTC and ~03:30 UTC on March 31, 2026 may have been impacted.

Upgrade to 3.2.1

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)