Unrated severityNVD Advisory· Published Jul 2, 2026· Updated Jul 2, 2026
obs-service-tar_scm: command injection via mercurial handler
CVE-2026-56004
Description
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.