uniget-org has 5 CVEs on record. 4 were published in the last 90 days. The median CVSS is 7.8 (high). None have a confirmed exploitation report. Most affected products: gitlab.com/uniget-org/cli (3), cli (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 4 prev 1
Worst active — by depth score
CVE-2026-55062High· 8.4uniget is a universal installer and updater for (container) tools58GHSA-fhgh-wq4q-r37xHigh· 7.8uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set43CVE-2026-45152High· 7.8uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution43CVE-2026-55061Low· 1.0uniget is a universal installer and updater for (container) tools6GO-2026-6246Noneuniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli3
uniget-org vulnerabilities
CVEs affecting uniget-org, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-55061Low· 1.0uniget is a universal installer and updater for (container) tools
uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as a…
CVE-2026-55062High· 8.4PoCuniget is a universal installer and updater for (container) tools
uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…
GO-2026-6246Noneuniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
GHSA-fhgh-wq4q-r37xHigh· 7.8uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
CVE-2026-45152High· 7.8uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution