unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments including --email and --password are output via JSON.stringify without sanitization, exposing secrets to shell history, CI/CD logs, and log aggregation systems. This vulnerability is fixed in 1.8.2.
References
Configurations
History
28 Feb 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Rageagainstthepixel
Rageagainstthepixel unity-cli |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| Summary |
|
|
| CPE | cpe:2.3:a:rageagainstthepixel:unity-cli:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/RageAgainstThePixel/unity-cli/commit/8d4d67b23d7c5fd8f00df3f0f10bec2961c95342 - Patch | |
| References | () https://github.com/RageAgainstThePixel/unity-cli/releases/tag/v1.8.2 - Release Notes | |
| References | () https://github.com/RageAgainstThePixel/unity-cli/security/advisories/GHSA-4255-c27h-62m5 - Vendor Advisory |
09 Feb 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 22:16
Updated : 2026-02-28 00:16
NVD link : CVE-2026-25918
Mitre link : CVE-2026-25918
CVE.ORG link : CVE-2026-25918
JSON object : View
Products Affected
rageagainstthepixel
- unity-cli
CWE
CWE-532
Insertion of Sensitive Information into Log File
