PT-2026-76893 · Unknown · Uniget Cli
CVE-2026-55061
·
Published
2026-08-17
·
Updated
2026-09-04
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
uniget CLI (affected versions not specified)
Description
The uniget CLI contains a command injection flaw during hook editing. The application retrieves the editor path from the
UNIGET EDITOR or EDITOR environment variables and uses the strings.Split() function to parse the string by spaces. Because this method does not respect shell syntax, an attacker can inject arbitrary commands by setting the environment variable to include shell operators. This issue was confirmed through a real-world exploit that executed the id command with user privileges.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict the use of the
EDITOR and UNIGET EDITOR environment variables to trusted values to minimize the risk of exploitation.Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uniget Cli