PT-2026-76894 · Unknown · Uniget Cli
CVE-2026-55062
·
Published
2026-08-17
·
Updated
2026-09-04
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
uniget CLI (affected versions not specified)
Description
A path traversal issue exists in the handling of hook filenames. The application fails to sanitize user input, allowing the direct concatenation of filenames with the hooks directory path. An attacker can use directory escape sequences, such as
../, to access and manipulate arbitrary files outside the intended hooks directory. This occurs within the hooks.go file where the hookFileName variable is used without validation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Uniget Cli