CVE-2026-104026
In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.
- Published Oct 2, 2026
- CVSS 7.8 high
- 0.1% chance of exploitation in the next 30 days (EPSS)
- A fix is available