CVE-2019-10802: Mangoraft Giting

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is executed by the package without any validation.

Affected products

  • Mangoraft Giting: before 0.0.8 (fixed in 0.0.8)

Published 2020-02-28. Last modified 2026-06-17.