Code Execution Vulnerability in Sapling SCM by JFrog
CVE-2026-104026

7.8HIGH

Key Information:

Vendor
CVE Published:
2 October 2026

What is CVE-2026-104026?

In versions of Sapling SCM before v0.2.20260929-102736, a vulnerability exists that allows untrusted control characters to be included in Git subtree URLs. This could potentially lead to code execution during normally safe operations like log, blame, or annotate when a malicious repository is cloned. Users should be aware of the risks associated with these URLs and take precautions to avoid being compromised.

Affected Version(s)

Sapling SCM v0.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.