๐Ÿ” CVE Alert

CVE-2026-2146

MEDIUM 6.3

guchengwuyue yshopmall co.yixiang.utils.FileUtil updateAvatar unrestricted upload

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-434 CWE-284
Vendor guchengwuyue
Product yshopmall
Published Feb 8, 2026
Last Updated Feb 23, 2026
Stay Ahead of the Next One

Get instant alerts for guchengwuyue yshopmall

Be the first to know when new medium vulnerabilities affecting guchengwuyue yshopmall are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

guchengwuyue / yshopmall
1.9.0 1.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.344848 vuldb.com: https://vuldb.com/?ctiid.344848 vuldb.com: https://vuldb.com/?submit.747409 github.com: https://github.com/guchengwuyue/yshopmall/issues/40 github.com: https://github.com/guchengwuyue/yshopmall/issues/40#issue-3860542812 github.com: https://github.com/guchengwuyue/yshopmall/

Credits

๐Ÿ” mukyuuhate (VulDB User)