Vendor
GitAhead versions 2.5.0 through 2.7.1 suffer from an insecure update mechanism that fails to verify update integrity, allowing attackers to perform a man-in-the-middle attack and execute arbitrary code.