CVE-2024-28886: Ameya/ayame Utau

High severity, CVSS 8.4. EPSS: 0.7% chance of exploitation in the next 30 days.

OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UTAU project file (.ust file), an arbitrary OS command may be executed.

Affected products

Published 2024-05-28. Last modified 2026-06-17.