CVE-2026-104026

Summary

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.

Affected Software

VendorProductVersion RangeStatus
Meta Platforms, IncSapling SCMv0.0.0 < v0.2.20260929-102736affected

Weaknesses

  • Improper Neutralization of Escape, Meta, or Control Sequences (CWE-150)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References