AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-1010260

HIGH · CVSS 8.1 EPSS 1.48% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-04-02 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-1010260
Severity
HIGH
CVSS
8.1
EPSS
1.48%

Original NVD Description

Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be compromised by a MITM. This attack is exploitable via Man in the Middle of the HTTP connection to the artifact servers. This vulnerability appears to have been fixed in 0.30.0 and later; after commit 5e547b287d6c260d328a2cb658dbe6b7a7ff2261.