BRIEFING NOTE - CVE-2026-34841 Bruno IDE versions prior to 3.2.1 were compromised through a supply chain attack involving the axios npm package, which contained a hidden Remote Access Trojan (RAT). The @usebruno/cli package was specifically affected, with compromised versions distributed during a narrow window on March 31, 2026 between 00:21 and approximately 03:30 UTC. The malicious dependency enables cross-platform remote access capabilities on affected systems. The vulnerability carries a critical CVSS score of 9.8, reflecting an unauthenticated network attack vector with low complexity and no user interaction required. The RAT provides complete compromise of confidentiality, integrity, and availability across affected machines, representing severe risk to any organization using the impacted package versions during the exposure window. Currently, there is no indication of active exploitation in the wild, as evidenced by the absence of a Known Exploited Vulnerabilities designation and the vulnerability's inactive status on threat intelligence hot lists. The EPSS score of 0.00026 suggests this attack has largely run its course from a supply chain perspective. Organizations should focus on immediate patching to version 3.2.1 and forensic analysis of systems that may have been compromised during the vulnerable distribution period.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.1CPE matchmatch criteria | cpe:2.3:a:usebruno:bruno:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.