AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-17T19:16:51.333Z and has not been modified since then. The hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, ' ') and passes every space-delimited suffix as an argument to the selected editor executable. An attacker who can influence the editor envir [truncated]
CVE-2026-45152 is a command injection vulnerability in uniget, a universal installer and updater for container tools. The flaw exists in versions prior to 0.27.1 and stems from unsafe execution of the `check` field from metadata files using `/bin/bash -c`. The `check` field is loaded directly from untrusted JSON metadata without validation or sanitization, allowing an attacker to craft malicious metadata [truncated]