Home

Description

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran npm install between 00:21 UTC and ~03:30 UTC on March 31, 2026 may have been impacted. Upgrade to 3.2.1

PUBLISHED Reserved 2026-03-30 | Published 2026-04-06 | Updated 2026-04-08 | Assigner GitHub_M




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-494: Download of Code Without Integrity Check

CWE-506: Embedded Malicious Code

Product status

< 3.2.1
affected

References

github.com/.../bruno/security/advisories/GHSA-658g-p7jg-wx5g

github.com/axios/axios/issues/10604

github.com/usebruno/bruno/pull/7632

www.aikido.dev/...os-npm-compromised-maintainer-hijacked-rat

cve.org (CVE-2026-34841)

nvd.nist.gov (CVE-2026-34841)

Download JSON