What is CVE-2026-16492?
This CVE describes an OS Command Injection vulnerability in the UmiJS framework (up to version 4.6.63), specifically within the `git.getFileCreateInfo` function in `getFileGitIno.ts`. As a public exploit exists, systems using the affected GIT File Helper component are at risk, and updating to the latest version is strongly recommended.
Azərbaycanca: Bu CVE, UmiJS framework-də (4.6.63-ə qədər versiyalarda) `getFileGitIno.ts` faylındakı `git.getFileCreateInfo` funksiyasında əmr inyeksiyası (OS Command Injection) zəifliyidir. İstismar kodu ictimaiyyətə açıq olduğu üçün bu komponentdən istifadə edən sistemlər təhlükə altındadır; dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
In which UmiJS component does the CVE-2026-16492 vulnerability reside?
The vulnerability resides in the `git.getFileCreateInfo` function within the `getFileGitIno.ts` file of the UmiJS framework.
Is there a publicly available exploit for CVE-2026-16492?
Yes, a public exploit exists for this vulnerability, putting affected systems at risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.