The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade gitlab.com/uniget-org/cli/cmd/uniget to version 0.27.6 or higher.
Affected versions of this package are vulnerable to Arbitrary Argument Injection due to the hook editor handling in cmd/uniget/hooks.go. An attacker can execute arbitrary commands by setting EDITOR or UNIGET_EDITOR to a value containing shell metacharacters and then invoking the hook editing command, which passes the split editor string to exec.Command as separate arguments. This allows the attacker-controlled editor setting to run unintended commands during hook editing, giving code execution with the privileges of the user running uniget and breaking hook-editing workflows for editors that rely on spaces in their command line.