{"id":"GHSA-vv9j-gjw2-j8wp","summary":"yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation","details":"### Impact\n\n`yeoman-environment` versions `\u003e= 2.9.0` and `\u003c 6.0.1` install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass attacker-controlled project configuration into this path, this can result in arbitrary package installation and code execution during CLI bootstrap.\n\nThe vulnerable method is `installLocalGenerators()`, which calls `repository.install()` directly without prompting the user.\n\n### Patches\n\nUpgrade to `yeoman-environment` `6.0.1`, which adds an interactive confirmation prompt before installation ([PR #753](https://github.com/yeoman/environment/pull/753)).\n\n### Workarounds\n\nNone.\n\n### Resources\n\n- [Fix commit 78d2af7](https://github.com/yeoman/environment/commit/78d2af7e60294784b8a8b3b3b5099c6874b6a1fa)","aliases":["CVE-2026-42089"],"modified":"2026-07-08T17:45:16.588278765Z","published":"2026-05-26T23:10:38Z","database_specific":{"nvd_published_at":"2026-06-16T17:16:40Z","cwe_ids":["CWE-829"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-05-26T23:10:38Z"},"references":[{"type":"WEB","url":"https://github.com/yeoman/environment/security/advisories/GHSA-vv9j-gjw2-j8wp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42089"},{"type":"WEB","url":"https://github.com/yeoman/environment/pull/753"},{"type":"WEB","url":"https://github.com/yeoman/environment/commit/78d2af7e60294784b8a8b3b3b5099c6874b6a1fa"},{"type":"PACKAGE","url":"https://github.com/yeoman/environment"}],"affected":[{"package":{"name":"yeoman-environment","ecosystem":"npm","purl":"pkg:npm/yeoman-environment"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.9.0"},{"fixed":"6.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-vv9j-gjw2-j8wp/GHSA-vv9j-gjw2-j8wp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}