Code Execution Vulnerability in Sapling SCM by JFrog
CVE-2026-104026
7.8HIGH
What is CVE-2026-104026?
In versions of Sapling SCM before v0.2.20260929-102736, a vulnerability exists that allows untrusted control characters to be included in Git subtree URLs. This could potentially lead to code execution during normally safe operations like log, blame, or annotate when a malicious repository is cloned. Users should be aware of the risks associated with these URLs and take precautions to avoid being compromised.
Affected Version(s)
Sapling SCM v0.0.0
