THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fhgh-wq4q-r37x (high) — uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

[GHSA] GHSA-fhgh-wq4q-r37x (high) — uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

highgithub_advisoriesPublished 2026-08-17

GHSA-fhgh-wq4q-r37x Severity: high CVE: None

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

## Summary

The sigstore check on `metadata.json` is gated on the wrong side of the condition. `LoadMetadata` in `internal/config/update.go:81` verifies the bundle only when `UNIGET_IGNORE_METADATA_SIGNATURE` is non-empty, so in a normal run, where nobod

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fhgh-wq4q-r37x