Description
In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.
Published:
2026-10-02
Score:
n/a
EPSS:
n/a
KEV:
No
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.facebook.com/security/advisories/cve-2026-104026 |
|
History
Fri, 02 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Meta
Published:
Updated: 2026-10-02T14:30:01.530Z
Reserved: 2026-10-01T17:11:09.874Z
Link: CVE-2026-104026
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.