top of page
perceptive_background_267k.jpg

uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution o…

Published:

26 mei 2026 om 22:00:00

Alert date:

27 mei 2026 om 23:01:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Security Tools

A critical command injection vulnerability (CVE-2026-45152) was discovered in uniget, a universal installer and updater for container tools. The vulnerability exists in versions prior to 0.27.1 due to unsafe execution of the check field from metadata files using /bin/bash -c. Attackers can craft malicious JSON metadata that executes arbitrary shell commands when common uniget operations like describe, install, update, or inspect are performed. The vulnerability leads to arbitrary code execution with the privileges of the user running uniget. The issue stems from loading the check field directly from untrusted JSON metadata without proper validation or sanitization. This vulnerability has been fixed in version 0.27.1.

Technical details

Mitigation steps:

Affected products:

uniget

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page