CVE-2026-104026 PUBLISHED

Assigner: Meta
Reserved: 01.10.2026 Published: 02.10.2026 Updated: 02.10.2026

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.

Product Status

Vendor Meta Platforms, Inc
Product Sapling SCM
Versions Default: unaffected
  • affected from v0.0.0 to v0.2.20260929-102736 (excl.)

References

Problem Types

  • Improper Neutralization of Escape, Meta, or Control Sequences (CWE-150)