CVE-2026-2146
guchengwuyue yshopmall co.yixiang.utils.FileUtil updateAvatar unrestricted upload
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
| CWE | CWE-434 CWE-284 |
| Vendor | guchengwuyue |
| Product | yshopmall |
| Published | Feb 8, 2026 |
| Last Updated | Feb 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for guchengwuyue yshopmall
Be the first to know when new medium vulnerabilities affecting guchengwuyue yshopmall are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
guchengwuyue / yshopmall
1.9.0 1.9.1
References
vuldb.com: https://vuldb.com/?id.344848 vuldb.com: https://vuldb.com/?ctiid.344848 vuldb.com: https://vuldb.com/?submit.747409 github.com: https://github.com/guchengwuyue/yshopmall/issues/40 github.com: https://github.com/guchengwuyue/yshopmall/issues/40#issue-3860542812 github.com: https://github.com/guchengwuyue/yshopmall/
Credits
๐ mukyuuhate (VulDB User)