CVE-2026-105295: GitAhead 2.5.0 through 2.7.1 Unverified Update Installation and TLS Bypass
GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid certificate once can intercept later automatic update checks, offer a fake version, and execute code as the user upon installation.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Users running GitAhead versions 2.5.0 through 2.7.1 are exposed when the application performs automatic update checks over a network an attacker can intercept. Exploitation ultimately requires the user to install the attacker-provided update.
What does an attacker need to do?
A network attacker must cause an SSL error dialog by presenting an invalid certificate during an update check. After TLS errors are permanently ignored, the attacker can intercept later update checks, present a fake version, and supply a malicious update.
What is the impact if exploitation succeeds?
The attacker can execute code with the privileges of the user who installs the malicious update. The reported impact includes compromise of confidentiality, integrity, and availability.
What can be done if patching is not immediately possible?
Avoid performing update checks or installing updates obtained through GitAhead's affected update mechanism on untrusted or interceptable networks. Do not accept SSL certificate errors during update checks, since one such error causes later TLS errors to be ignored permanently.