GHSA-fhgh-wq4q-r37x: uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
highvulnerability
security
Source: GitHub Advisory DatabaseAugust 17, 2026
Summary
The uniget CLI has a logic error where signature verification for metadata.json (a configuration file that lists tools to install) only runs when the UNIGET_IGNORE_METADATA_SIGNATURE environment variable is set, which is backwards—it should verify signatures by default. This flaw allows an attacker to inject malicious commands into the metadata that get executed through bash, bypassing the security check that was added in version 0.27.1 to prevent this type of attack.
Classification
Attack SophisticationModerate
Affected Packages
gitlab.com/uniget-org/cli@>= 0.27.4, < 0.28.9 (fixed: 0.28.9)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-fhgh-wq4q-r37x
First tracked: August 17, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%