logo

Microsoft MSRC Allegedly Declines Action on Dependency Confusion Vulnerability

ID: dc0291ae-f485-5493-8807-25b655092bf6

STIX ID: report--dc0291ae-f485-5493-8807-25b655092bf6

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Divya

...
...

A security researcher demonstrated a dependency confusion issue in Azure Portal assets by claiming an unregistered internal npm namespace and publishing a package that produced an out-of-band callback from Microsoft infrastructure, exposing execution context; MSRC closed the report as non-exploitable (attributing activity to internal tooling) despite PoC RCE evidence and the package being added to the GitHub Advisory Database with a CVSS 9.3 rating, underscoring supply-chain risks to external developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.