๐Ÿ” CVE Alert

CVE-2026-104026

HIGH 7.8
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.

Vendor meta platforms, inc
Product sapling scm
Published Oct 2, 2026
Last Updated Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for meta platforms, inc sapling scm

Be the first to know when new high vulnerabilities affecting meta platforms, inc sapling scm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Meta Platforms, Inc / Sapling SCM
v0.0.0 < v0.2.20260929-102736

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
facebook.com: https://www.facebook.com/security/advisories/cve-2026-104026