GO-2026-6246None▾ Sunlituniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
gitlab.com/uniget-org/cli >= 0.27.4, < 0.28.9Upgrade to a patched release:
gitlab.com/uniget-org/cli 0.28.9Connected by shared product, vendor, weakness, or advisory.
GHSA-fhgh-wq4q-r37xHigh· 7.8uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
CVE-2026-45152High· 7.8uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
CVE-2026-55061Low· 1.0uniget is a universal installer and updater for (container) tools
CVE-2026-55062High· 8.4uniget is a universal installer and updater for (container) tools