CVE-2026-42089
HIGHDescription
Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass attacker-controlled project configuration into this path, this can result in arbitrary package installation and code execution during CLI bootstrap. The vulnerable method is installLocalGenerators(), which calls repository.install() directly without prompting the user. This issue has been fixed in version 6.0.0.
Is your site exposed to CVE-2026-42089?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-42089? +
How severe is CVE-2026-42089? +
How do I check if I'm vulnerable to CVE-2026-42089? +
Related Vulnerabilities
A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input …
Collabora Online is a collaborative online office suite based on LibreOffice. Macro support is disabled by default in Collabora Online, …
In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The …
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the repository …
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution …
Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model …