CVE-2026-16492
Last modified
CVE-2026-16492 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the component GIT File Helper. EPSS estimates a 1.66% chance of exploitation in the next 30 days.
Description
A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the component GIT File Helper. This manipulation causes os command injection. The exploit has been made available to the public and could be used for attacks. Upgrading to version 4.6.64 is sufficient to fix this issue. Patch name: b6da12c17b024a43badb1fa565720c38cf42e647. Upgrading the affected component is advised.
Metrics
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| umijs | umi | 4.6.0; 4.6.1; 4.6.2; 4.6.3; 4.6.4; 4.6.5; 4.6.6; 4.6.7; 4.6.8; 4.6.9; 4.6.10; 4.6.11; 4.6.12; 4.6.13; 4.6.14; 4.6.15; 4.6.16; 4.6.17; 4.6.18; 4.6.19; 4.6.20; 4.6.21; 4.6.22; 4.6.23; 4.6.24; 4.6.25; 4.6.26; 4.6.27; 4.6.28; 4.6.29; 4.6.30; 4.6.31; 4.6.32; 4.6.33; 4.6.34; 4.6.35; 4.6.36; 4.6.37; 4.6.38; 4.6.39; 4.6.40; 4.6.41; 4.6.42; 4.6.43; 4.6.44; 4.6.45; 4.6.46; 4.6.47; 4.6.48; 4.6.49; 4.6.50; 4.6.51; 4.6.52; 4.6.53; 4.6.54; 4.6.55; 4.6.56; 4.6.57; 4.6.58; 4.6.59; 4.6.60; 4.6.61; 4.6.62; 4.6.63 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-16492?
How severe is CVE-2026-16492?
How do I fix CVE-2026-16492?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-16485A vulnerability has been found in SourceCodester Class and E…4.3
- CVE-2026-16486A vulnerability was found in SourceCodester Class and Exam T…4.3
- CVE-2026-16488A vulnerability was determined in QUSETIONS MiniCode-Python …5
- CVE-2026-16489A vulnerability was identified in jsforce up to 3.10.16. Thi…5.3
- CVE-2026-1649The Community Events plugin for WordPress is vulnerable to S…4.4
- CVE-2026-16490A security flaw has been discovered in itsourcecode Hospital…6.3
- CVE-2026-16493A flaw was found in ansible-core. The _extract_collection_fr…7.8
- CVE-2026-16496The terraform-mcp-server before version 1.1.0 is vulnerable …8.9
- CVE-2026-16498The terraform-mcp-server before version 1.1.0 is vulnerable …10
- CVE-2026-1650The MDJM Event Management plugin for WordPress is vulnerable…5.3
- CVE-2026-1651The Email Subscribers by Icegram Express plugin for WordPres…6.5
- CVE-2026-16517A signed integer overflow vulnerability was found in libarch…2.9
Are you affected by CVE-2026-16492?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
