High severity7.8NVD Advisory· Published Oct 2, 2026
CVE-2026-104026
CVE-2026-104026
Description
In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <v0.2.20260929-102736
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.