CVE-2026-25918

unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments including --email and --password are output via JSON.stringify without sanitization, exposing secrets to shell history, CI/CD logs, and log aggregation systems. This vulnerability is fixed in 1.8.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rageagainstthepixel:unity-cli:*:*:*:*:*:node.js:*:*

History

28 Feb 2026, 00:16

Type Values Removed Values Added
First Time Rageagainstthepixel
Rageagainstthepixel unity-cli
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
Summary
  • (es) unity-cli es una utilidad de línea de comandos para el motor de juego Unity. Antes de 1.8.2, el comando sign-package en @rage-against-the-pixel/unity-cli registra credenciales sensibles en texto plano cuando se utiliza la bandera --verbose. Los argumentos de línea de comandos, incluyendo --email y --password, se emiten a través de JSON.stringify sin sanitización, exponiendo secretos al historial de la shell, a los registros de CI/CD y a los sistemas de agregación de registros. Esta vulnerabilidad está corregida en 1.8.2.
CPE cpe:2.3:a:rageagainstthepixel:unity-cli:*:*:*:*:*:node.js:*:*
References () https://github.com/RageAgainstThePixel/unity-cli/commit/8d4d67b23d7c5fd8f00df3f0f10bec2961c95342 - () https://github.com/RageAgainstThePixel/unity-cli/commit/8d4d67b23d7c5fd8f00df3f0f10bec2961c95342 - Patch
References () https://github.com/RageAgainstThePixel/unity-cli/releases/tag/v1.8.2 - () https://github.com/RageAgainstThePixel/unity-cli/releases/tag/v1.8.2 - Release Notes
References () https://github.com/RageAgainstThePixel/unity-cli/security/advisories/GHSA-4255-c27h-62m5 - () https://github.com/RageAgainstThePixel/unity-cli/security/advisories/GHSA-4255-c27h-62m5 - Vendor Advisory

09 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 22:16

Updated : 2026-02-28 00:16


NVD link : CVE-2026-25918

Mitre link : CVE-2026-25918

CVE.ORG link : CVE-2026-25918


JSON object : View

Products Affected

rageagainstthepixel

  • unity-cli
CWE
CWE-532

Insertion of Sensitive Information into Log File