PatchSiren cyber security CVE debrief
CVE-2026-45152 uniget-org CVE debrief
CVE-2026-45152 is a command injection vulnerability in uniget, a universal installer and updater for container tools. The flaw exists in versions prior to 0.27.1 and stems from unsafe execution of the `check` field from metadata files using `/bin/bash -c`. The `check` field is loaded directly from untrusted JSON metadata without validation or sanitization, allowing an attacker to craft malicious metadata that executes arbitrary shell commands when common uniget operations (describe, install, update, inspect) are performed. This results in arbitrary code execution with the privileges of the user running uniget. The vulnerability was published on 2026-05-27 and is fixed in version 0.27.1.
- Vendor
- uniget-org
- Product
- cli
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-05-28
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-05-28
Who should care
Organizations and developers using uniget for container tool management, particularly those consuming metadata from external or untrusted sources. Security teams monitoring supply chain risks in container tooling ecosystems.
Technical summary
The uniget tool executes a `check` field from JSON metadata using `/bin/bash -c` without input validation or sanitization. An attacker can supply malicious metadata containing shell metacharacters or command substitution sequences. When a user performs operations such as describe, install, update, or inspect, the uniget tool retrieves and executes the attacker-controlled `check` field, resulting in arbitrary command execution with the user's privileges. The vulnerability is classified as CWE-78 (OS Command Injection).
Defensive priority
HIGH
Recommended defensive actions
- Upgrade uniget to version 0.27.1 or later to remediate this vulnerability.
- Review and audit any custom or third-party metadata files used with uniget for malicious content if operating unpatched versions.
- Restrict uniget execution to isolated environments with minimal privileges until patching is complete.
- Monitor for suspicious shell execution patterns originating from uniget processes in endpoint detection systems.
Evidence notes
The vulnerability description indicates the `check` field from JSON metadata is executed via `/bin/bash -c` without validation. Common operations like describe, install, update, and inspect trigger this execution path. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates local attack vector with user interaction required, but high impact on confidentiality, integrity, and availability.
Official resources
-
CVE-2026-45152 CVE record
CVE.org
-
CVE-2026-45152 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-05-27