AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-19604

HIGH · CVSS 7.8 EPSS 3.69%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-12-11 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-19604
Severity
HIGH
CVSS
7.8
EPSS
3.69%

Original NVD Description

Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.