Insecure Update Mechanism in GitAhead Affects Multiple Versions
CVE-2026-105295
7.7HIGH
What is CVE-2026-105295?
GitAhead versions 2.5.0 to 2.7.1 include a flaw that permits an insecure update mechanism. This vulnerability allows updates to be installed without verifying their integrity or signatures. Moreover, it ignores TLS errors after a single SSL dialog, creating an opportunity for network attackers to exploit the system. If an attacker presents a bogus certificate, they can intercept future update checks and potentially deliver malicious versions of the software, which could execute code with the same privileges as the user.
Affected Version(s)
GitAhead 2.5.0 <= 2.7.1
