AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-28886

HIGH · CVSS 8.4 EPSS 0.66%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-05-28 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.4. See the original NVD description below for full technical details.

CVE
CVE-2024-28886
Severity
HIGH
CVSS
8.4
EPSS
0.66%

Original NVD Description

OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UTAU project file (.ust file), an arbitrary OS command may be executed.