PatchSiren cyber security CVE debrief
CVE-2026-16492 umijs CVE debrief
A weakness has been identified in umijs umi up to 4.6.63, specifically in the git.getFileCreateInfo function of the getFileGitIno.ts file within the GIT File Helper component. This manipulation leads to os command injection, allowing attackers to execute arbitrary commands on the affected system. The exploit has been made publicly available, increasing the risk of attacks. Upgrading to version 4.6.64 is sufficient to fix this issue. The vulnerability has a CVSS score of 2 and is classified as LOW severity. However, the public availability of the exploit and the potential for os command injection necessitate immediate attention from users of the affected component.
- Vendor
- umijs
- Product
- umi
- CVSS
- LOW 2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Users of umijs umi up to version 4.6.63 should be aware of this vulnerability and take steps to upgrade to version 4.6.64 or apply compensating controls. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact on their systems and plan for remediation. The vulnerability's impact on operational security and potential for os command injection requires immediate attention from affected stakeholders.
Technical summary
The vulnerability exists in the git.getFileCreateInfo function of the getFileGitIno.ts file in the packages/utils/src directory of umijs umi up to 4.6.63. This function is part of the GIT File Helper component. The vulnerability allows for os command injection, which could be exploited by attackers to execute arbitrary commands on the affected system. The issue has been addressed in version 4.6.64 with the patch b6da12c17b024a43badb1fa565720c38cf42e647. Users should review their deployments and apply the necessary updates or mitigations.
Defensive priority
Low
Recommended defensive actions
- Upgrade umijs umi to version 4.6.64 or later
- Apply compensating controls to mitigate the risk of os command injection
- Monitor systems for suspicious activity related to the GIT File Helper component
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-22T01:16:26.257Z and was last modified on 2026-07-22T16:25:46.380Z. The NVD entry is currently Deferred. The source item URL for CVE-2026-16492 is available. The official CVE record and NVD detail page provide additional information. However, the current information has limitations, and defenders should verify the affected scope and severity with the vendor. The exploit has been made available publicly, increasing the urgency for affected users to apply mitigations.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T01:16:26.257Z and has not been modified since then. The NVD entry is currently Deferred.