MEDIUM GitHub

CVE-2026-55061

uniget CLI has an EDITOR Command Injection

### Summary The uniget CLI has a command injection vulnerability in [hooks.go](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/code/electron-browser/workbench/workbench.html) line 199 where [strings.Split(editor, " ")](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/code/electron-browser/workbench/workbench.html) naively parses the EDITOR environment variable without respecting shell syntax. An attacker can set EDITOR="/path/to/wrapper && id && echo" which gets spli

Affected Products

References

Published: 2026-08-17 · Source: GitHub · Feed updated: 2026-08-17
This medium severity vulnerability was published on 2026-08-17 via GitHub. Affected: go/gitlab.com/uniget-org/cli < 0.27.6.
vulnfeed aggregates 11030 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.