CVE-2018-19486: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 4.1% chance of exploitation in the next 30 days.
Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 18.10 only
- Git-Scm Git: before 2.19.2 (fixed in 2.19.2)
Published 2018-11-23. Last modified 2026-06-17.