PT-2026-7170 · Unity · Unity-Cli

·

CVE-2026-25918

·

Published

2026-02-09

·

Updated

2026-02-28

CVSS v4.0

5.9

Medium

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions unity-cli versions prior to 1.8.2
Description The sign-package command in unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments, including --email and --password, are output via JSON.stringify without sanitization, potentially exposing secrets to shell history, CI/CD logs, and log aggregation systems. The vulnerable parameters are email and password.
Recommendations Update to version 1.8.2 or later.

Exploit

Fix

CSRF

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25918
GHSA-4255-C27H-62M5

Affected Products

Unity-Cli