GHSA-g4x4-gm4c-5r8hHighCVSS 7.8

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in...

Published
October 2, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (1)

📋 Description

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.

🔗 References (3)