THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qmcq-xw74-w667 (medium) — uniget CLI has an EDITOR Command Injection

[GHSA] GHSA-qmcq-xw74-w667 (medium) — uniget CLI has an EDITOR Command Injection

medgithub_advisoriesPublished 2026-08-17

GHSA-qmcq-xw74-w667 Severity: medium CVE: CVE-2026-55061

uniget CLI has an EDITOR Command Injection

### Summary The uniget CLI has a command injection vulnerability in [hooks.go](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/code/electron-browser/workbench/workbench.html) line 199 where [strings.Split(editor, " ")](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/c

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qmcq-xw74-w667