Vulnerability record · CVE-2026-34841 · published 6 April 2026
CVE-2026-34841: Usebruno bruno download of code without integrity check vulnerability
Usebruno · Bruno
Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran npm install between 00:21 UTC and ~03:30 UTC on March 31, 2026 may have been impacted. Upgrade to 3.2.1
Description
Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran npm install between 00:21 UTC and ~03:30 UTC on March 31, 2026 may have been impacted. Upgrade to 3.2.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/axios/axios/issues/10604 | Issue Tracking |
| https://github.com/usebruno/bruno/pull/7632 | Issue TrackingPatch |
| https://github.com/usebruno/bruno/security/advisories/GHSA-658g-p7jg-wx5g | MitigationPatchVendor Advisory |
| https://www.aikido.dev/blog/axios-npm-compromised-maintainer-hijacked-rat | MitigationPress/Media Coverage |
Track CVE-2026-34841 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-34841), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.