Impact
uniget CLI parses the editor command by splitting on spaces and passes each token to the editor executable when a hook edit is invoked. If an attacker can influence the UNIGET_EDITOR or EDITOR environment variable, they can inject unexpected arguments. This allows the attacker to exercise unintended actions with the privileges of the uniget process account. The code does not evaluate shell operators, so the injection is limited to argument manipulation rather than full shell command interpretation.
Affected Systems
uniget-cli, version 0.27.5 and earlier. The vulnerability affects all installations of the CLI that use the hook edit command prior to version 0.27.6.
Risk and Exploitability
The CVSS score of 1 and EPSS score of less than 1% indicate a low severity and low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker who can set environment variables in the context of the uniget process, making it a local privilege or configuration issue rather than a remote attack vector.
OpenCVE Enrichment
Github GHSA