Description
uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as an argument to the selected editor executable. An attacker who can influence the editor environment and cause hook editing can supply unexpected editor arguments, potentially causing unintended actions with the privileges of the uniget process account. Go os/exec does not evaluate shell operators in these arguments, so the advisory's wrapper demonstration establishes argument delivery but does not establish shell command interpretation. This issue is fixed in version 0.27.6.
Published: 2026-09-17
Score: 1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Command Injection
Action: Patch
AI Analysis

Impact

uniget CLI parses the editor command by splitting on spaces and passes each token to the editor executable when a hook edit is invoked. If an attacker can influence the UNIGET_EDITOR or EDITOR environment variable, they can inject unexpected arguments. This allows the attacker to exercise unintended actions with the privileges of the uniget process account. The code does not evaluate shell operators, so the injection is limited to argument manipulation rather than full shell command interpretation.

Affected Systems

uniget-cli, version 0.27.5 and earlier. The vulnerability affects all installations of the CLI that use the hook edit command prior to version 0.27.6.

Risk and Exploitability

The CVSS score of 1 and EPSS score of less than 1% indicate a low severity and low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker who can set environment variables in the context of the uniget process, making it a local privilege or configuration issue rather than a remote attack vector.

Generated by OpenCVE AI on September 18, 2026 at 23:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade uniget CLI to version 0.27.6 or later
  • Unset the UNIGET_EDITOR and EDITOR environment variables before running uniget commands or ensure they originate only from trusted sources
  • If upgrading immediately is not possible, restrict the execution of uniget commands to trusted users and consider disabling the hook edit feature until a patch is applied

Generated by OpenCVE AI on September 18, 2026 at 23:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qmcq-xw74-w667 uniget CLI has an EDITOR Command Injection
History

Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Uniget-org
Uniget-org cli
Vendors & Products Uniget-org
Uniget-org cli

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as an argument to the selected editor executable. An attacker who can influence the editor environment and cause hook editing can supply unexpected editor arguments, potentially causing unintended actions with the privileges of the uniget process account. Go os/exec does not evaluate shell operators in these arguments, so the advisory's wrapper demonstration establishes argument delivery but does not establish shell command interpretation. This issue is fixed in version 0.27.6.
Title uniget: EDITOR Command Injection in uniget CLI
Weaknesses CWE-88
References
Metrics cvssV4_0

{'score': 1, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T14:44:09.945Z

Reserved: 2026-06-16T14:33:35.709Z

Link: CVE-2026-55061

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-17T19:16:51.333

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-55061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:00:12Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')