Critical severity10.0NVD Advisory· Published Jul 2, 2026· Updated Jul 2, 2026
CVE-2026-56004
CVE-2026-56004
Description
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services
Affected products
2- Range: <0.12.4
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.