PT-2026-76893 · Unknown · Uniget Cli

CVE-2026-55061

·

Published

2026-08-17

·

Updated

2026-09-04

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions uniget CLI (affected versions not specified)
Description The uniget CLI contains a command injection flaw during hook editing. The application retrieves the editor path from the UNIGET EDITOR or EDITOR environment variables and uses the strings.Split() function to parse the string by spaces. Because this method does not respect shell syntax, an attacker can inject arbitrary commands by setting the environment variable to include shell operators. This issue was confirmed through a real-world exploit that executed the id command with user privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict the use of the EDITOR and UNIGET EDITOR environment variables to trusted values to minimize the risk of exploitation.

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55061
GHSA-QMCQ-XW74-W667
GO-2026-6248
OPENSUSE-SU-2026:21761-1

Affected Products

Uniget Cli