{"@context":"https://openvex.dev/ns/v0.2.0","@id":"https://database.harborguard.co/cve/CVE-2026-42089/vex.json","author":"HarborGuard Database","role":"Document Creator","timestamp":"2026-06-16T17:24:07.061Z","version":1,"tooling":"HarborGuard Database (https://database.harborguard.co)","statements":[{"vulnerability":{"name":"CVE-2026-42089","@id":"https://www.cve.org/CVERecord?id=CVE-2026-42089","description":"Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass attacker-controlled project configuration into this path, this can result in arbitrary package installation and code execution during CLI bootstrap. The vulnerable method is installLocalGenerators(), wh"},"products":[{"@id":"cpe:2.3:a:yeoman:environment:\\>\\=_2.9.0\\,_\\<_6.0.1:*:*:*:*:*:*:*","identifiers":{"cpe23":"cpe:2.3:a:yeoman:environment:\\>\\=_2.9.0\\,_\\<_6.0.1:*:*:*:*:*:*:*"}}],"status":"affected","action_statement":"No fixed version is published yet; monitor the upstream advisory.","timestamp":"2026-06-16T17:24:07.061Z"}]}