CVE Feed

    Dashboard / CVE / CVE-2026-42089

    CVE-2026-42089

    Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass attacker-controlled project configuration into this path, this can result in arbitrary package installation and code execution during CLI bootstrap. The vulnerable method is installLocalGenerators(), which calls repository.install() directly without prompting the user. This issue has been fixed in version 6.0.0.

    Published:Jun 16, 2026
    Last Modified:Jun 23, 2026
    EPS:Jun 16, 2026
    EPSS Score:0.00139
    CVSS Score:8.6

    Affected Products

    Vendor
    Yeoman
    Product
    Environment

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High