Listen to this Post
The vulnerability resides in the hook filename handling logic within the uniget CLI tool. Specifically, the `hooks.go` file, at lines 135-160, processes user-supplied hook filenames via the `args
` parameter without any validation or sanitization. This unsanitized input is then directly concatenated with the `preInstallHooksDir` path using a simple string operation: <code>hookFile = preInstallHooksDir + "/" + hookFileName</code>. Because the application fails to check for directory traversal sequences such as <code>../</code>, an attacker can craft a hook filename containing these escape sequences to traverse outside the intended hooks directory. This allows the attacker to read, and potentially manipulate, arbitrary files on the underlying filesystem to which the uniget process has access. The vulnerability is triggered when a user executes a command like `./uniget hooks edit --type=pre-install` and provides a malicious hook filename. The editor specified by the `EDITOR` environment variable is then invoked on the constructed file path, leading to the exposure of sensitive system files such as <code>/etc/passwd</code>. <h2 style="color: blue;">DailyCVE Form:</h2> Platform: uniget CLI Version: <0.27.6 Vulnerability: Path Traversal Severity: Moderate date: 2026-08-17 <h2 style="color: blue;">Prediction: 2026-08-18</h2> <h2 style="color: blue;">What Undercode Say:</h2> [bash] Identify the vulnerable version uniget version Exploit the path traversal to read /etc/passwd export EDITOR="cat" ./uniget hooks edit --type=pre-install "../../../../etc/passwd"
Exploit: (Educational Purposes!)
The proof of concept demonstrates how an attacker can leverage the `EDITOR` environment variable to read arbitrary files:
1. Set the `EDITOR` to `cat` to display file contents:
export EDITOR="cat"
2. Execute the `hooks edit` command with a path traversal payload:
./uniget hooks edit --type=pre-install "../../../../etc/passwd"
3. The contents of `/etc/passwd` are printed to the console, confirming the path traversal.
Protection:
The fix, implemented in commit `7b4f18a` and released in version v0.27.6, introduces proper path sanitization. The resolution involves using `filepath.Abs()` to resolve the absolute path of the hook file and then verifying that this absolute path is within the intended `hooksDir` using strings.HasPrefix(). If the path is outside the directory, an error is returned, effectively blocking the traversal attack. Users are strongly advised to upgrade to the latest patched version.
Impact:
Successful exploitation allows an attacker to read sensitive system files (e.g., /etc/passwd, /etc/shadow) and potentially access or modify other arbitrary files accessible by the uniget process. This can lead to information disclosure, privilege escalation, or further compromise of the system depending on the permissions of the uniget process and the contents of the files accessed.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

