CVE-2026-2146 | guchengwuyue yshopmall up to 1.9.1 co.yixiang.utils.FileUtil /api/users/updateAvatar File unrestricted upload (Issue 40 / EUVD-2026-5803)
A vulnerability classified as critical has been found in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload.
This vulnerability is reported as CVE-2026-2146. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.