PatchSiren

umijs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW umijs CVE published 2026-07-22

CVE-2026-16492

A weakness has been identified in umijs umi up to 4.6.63, specifically in the git.getFileCreateInfo function of the getFileGitIno.ts file within the GIT File Helper component. This manipulation leads to os command injection, allowing attackers to execute arbitrary commands on the affected system. The exploit has been made publicly available, increasing the risk of attacks. Upgrading to version 4.6.64 is s [truncated]