CVE-2026-104026
Received Received - Intake

Control Character Injection in Sapling SCM

Vulnerability report for CVE-2026-104026, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Facebook, Inc.

Description

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sapling_scm sapling_scm to 0.2.20260929-102736 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-150 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in Sapling SCM versions before v0.2.20260929-102736. It allows control characters to be embedded in Git subtree URLs. An attacker could create a malicious repository that, when cloned by a victim, executes arbitrary code even during read-only operations like viewing logs or annotations.

Detection Guidance

To detect this vulnerability, check the version of Sapling SCM installed on your system. Run: sapling --version. If the version is prior to v0.2.20260929-102736, the system is vulnerable. Additionally, review cloned repositories for suspicious Git subtree URLs containing control characters.

Impact Analysis

If you use an affected Sapling SCM version, cloning a malicious repository could lead to arbitrary code execution on your system. This happens even during seemingly safe actions like running sl log, blame, or annotate commands. The attacker gains full control over your system with the same privileges as your user account.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially causing data breaches or unauthorized access to sensitive information. This may violate compliance requirements under GDPR (data protection), HIPAA (health data security), or other regulations mandating access controls and auditability.

Mitigation Strategies

Upgrade Sapling SCM to version v0.2.20260929-102736 or later to address the control character issue in Git subtree URLs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104026. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart