Description
GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid certificate once can intercept later automatic update checks, offer a fake version, and execute code as the user upon installation.
Published: 2026-10-05
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

GitAhead versions 2.5.0 through 2.7.1 implement an insecure update mechanism that installs downloaded updates without any integrity or signature verification (CWE‑494). After a single TLS error dialog, the application permanently suppresses all future TLS errors, allowing a malicious actor to perform a man‑in‑the‑middle attack. The combined effect permits an attacker to supply a forged update that, when installed, results in arbitrary code execution with the privileges of the installing user.

Affected Systems

The vulnerable revisions are GitAhead 2.5.0 to 2.7.1. The CVE data does not specify any operating‑system restrictions; therefore every installation of these versions on supported platforms is considered vulnerable.

Risk and Exploitability

The CVSS score of 7.7 categorizes the flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in the KEV catalog, indicating a moderate exploitation likelihood. Attackers need only to intercept the TLS handshake between the client and the official update server; after the user dismisses the initial TLS error, the client will silently trust subsequent connections. By supplying a malicious update payload, the attacker can trigger code execution without additional user interaction, making the flaw readily exploitable in environments lacking strict network controls.

Generated by OpenCVE AI on October 5, 2026 at 03:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy a validated fix or move to a newer GitAhead release that includes proper integrity verification and TLS error handling as soon as it becomes available.
  • Restrict outbound traffic from GitAhead to only the officially signed update server and configure the firewall or proxy to reject connections presenting untrusted TLS certificates.
  • Disable automatic updates and require administrators to manually verify the authenticity of update files before installation, using checksums or digital signatures where possible.

Generated by OpenCVE AI on October 5, 2026 at 03:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 01:00:00 +0000

Type Values Removed Values Added
Description GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid certificate once can intercept later automatic update checks, offer a fake version, and execute code as the user upon installation.
Title GitAhead 2.5.0 through 2.7.1 Unverified Update Installation and TLS Bypass
Weaknesses CWE-494
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-05T00:44:19.994Z

Reserved: 2026-10-05T00:19:12.681Z

Link: CVE-2026-105295

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T01:16:29.063

Modified: 2026-10-05T01:16:29.063

Link: CVE-2026-105295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T03:45:19Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check