PT-2026-76894 · Unknown · Uniget Cli

CVE-2026-55062

·

Published

2026-08-17

·

Updated

2026-09-04

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions uniget CLI (affected versions not specified)
Description A path traversal issue exists in the handling of hook filenames. The application fails to sanitize user input, allowing the direct concatenation of filenames with the hooks directory path. An attacker can use directory escape sequences, such as ../, to access and manipulate arbitrary files outside the intended hooks directory. This occurs within the hooks.go file where the hookFileName variable is used without validation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55062
GHSA-M6JG-WR9M-CG2F
GO-2026-6247
OPENSUSE-SU-2026:21761-1

Affected Products

Uniget Cli