CVE-2026-34841Disclosure(usebruno / bruno)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for usebruno bruno systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran npm install between 00:21 UTC and ~03:30 UTC on March 31, 2026 may have been impacted. Upgrade to 3.2.1

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-494CWE-506

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bruno

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-06)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
bruno

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-03: 1Mentions · 2026-04-06: 3PoC Mentioned / Linked · 2026-04-06: 1Active Exploitation · 2026-04-06: 1Technical Details · 2026-04-06: 304-0304-06
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-031
General1
2026-04-063
Active Exploitation1Disclosure2
Full discourse4 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-34841: CRITICAL] Beware of cyber security risks! Bruno IDE faced a supply chain attack through a compromised axios npm package, potentially deploying a Remote Access Trojan. Secure your system with...#cve,CVE-2026-34841,#cybersecurity https://cvefind.com/CVE-2026-34841

    Post summary

    The post highlights a new critical vulnerability (CVE‑2026‑34841) that involves a compromised axios npm package, posing a supply chain risk and potential Remote Access Trojan deployment, but it does not provide evidence of active exploitation, exploit tools, or patches.

    00010156
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34841 Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios np… https://www.cve.org/CVERecord?id=CVE-2026-34841

    Post summary

    The text announces a supply chain vulnerability (CVE-2026-34841) in the Bruno IDE, noting that versions before 3.2.1 were affected due to compromised axios packages, but does not detail exploit code or mitigation steps.

    00000133
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Active Exploitation

    🚨 CVE-2026-34841: Axios npm Supply Chain Incident ... Axios maintainer hijack deployed RAT to Bruno CLI users during 3-hour window - classic npm supply chain pwn with perfec... https://zerodaysignal.com/vulnerability/CVE-2026-34841 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-34841, an npm supply chain vulnerability in Axios, was actively exploited with a RAT deployed to Bruno CLI users over a 3‑hour window, and the text links to a detailed article.

    00000123
    204 followersView on X
  • PulsePatch.io@pulsepatchio
    General

    A supply chain incident affecting the `Axios` npm package, impacting `@usebruno/cli`, is identified as CVE-2026-34841. Users should monitor for official updates and audit dependencies. #SupplyChain #npm #infosec https://www.pulsepatch.io/posts/cve-2026-34841-axios-npm-supply-chain-incident

    Post summary

    The post notes a supply‑chain incident affecting Axios (CVE‑2026‑34841) but does not provide technical details, exploitation evidence, or patch information, merely advising users to watch for updates.

    0000034
    10 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appusebrunobruno---

Explore more