Junglewise Threat Intelligence

CVE-2026-16492: umijs Umi OS command injection in GIT File Helper

CVE-2026-16492 · Severity: medium · CVSS 5.5 · Published 2026-07-22

Executive brief

Umi, a popular React framework, contains a vulnerability in its utility package that handles Git metadata. If an application or tool using this library processes a specially crafted file path, an attacker could execute unauthorized commands on the underlying system. This could lead to a full system compromise or unauthorized access to sensitive data within the development or deployment environment.

Technical details

An OS command injection vulnerability exists in @umijs/utils (part of the Umi framework) within the git.getFileCreateInfo and git.getFileLastModifyInfo functions. The root cause is the use of cross-spawn with the { shell: true } option while passing a user-controlled filePath argument without proper sanitization. An attacker who can influence the file path passed to these helper functions can inject shell metacharacters (e.g., semicolons) to execute arbitrary commands with the privileges of the Node.js process. The issue is fixed in version 4.6.64 by disabling shell execution and using the '--' positional argument separator for Git commands.

Affected products

  • umijs umi up to 4.6.63

Timeline

  • 2026-06-16: disclosed: Issue reported on GitHub
  • 2026-06-16: patched: Fix merged via pull request #13347
  • 2026-07-22: advisory: CVE published to NVD

References