CVE-2026-25918Disclosure(rageagainstthepixel / unity-cli)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments including --email and --password are output via JSON.stringify without sanitization, exposing secrets to shell history, CI/CD logs, and log aggregation systems. This vulnerability is fixed in 1.8.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unity-cli

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-10)
  • 3 total mentions across 2 days

Affected systems

Products
unity-cli

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-09: 1Mentions · 2026-02-10: 2Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 202-0902-10
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-102
Disclosure1General1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25918 Credential Exposure Vulnerability in Unity CLI @rage-against-the-pixel/unity-cli Before 1.8.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25918

    Post summary

    The entry lists CVE-2026-25918 as a credential exposure issue affecting Unity CLI versions prior to 1.8.2, pointing to a vulnerability details page without further technical or mitigation information.

    00010108
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25918 unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentia… https://www.cve.org/CVERecord?id=CVE-2026-25918

    Post summary

    The CVE‑2026‑25918 vulnerability in unity‑cli causes the sign‑package command to log sensitive credentials on releases before 1.8.2. No exploitation or patch information is provided.

    00010174
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25918: Game Over: Unity-CLI Spills Secrets in Verbose Mode In the world of DevOps, visibility is everything. We want logs, metrics, and traces. But sometimes, tools give us a little *too much* visibility. The `unity-cli` tool, a popular wrapp... https://cvereports.com/reports/CVE-2026-25918

    Post summary

    The report announces that Unity-CLI’s verbose mode leaks secrets, but no PoC, exploit, active usage, or patch is discussed.

    0000048
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprageagainstthepixelunity-cli-node.js-

Explore more