CVE-2026-104026: High severity Sapling Sapling SCM vulnerability
Published Oct 2, 2026
·Updated
In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.
Affected Software
1 affected component
Sapling Sapling SCM<v0.2.20260929-102736
Event History
Oct 2, 2026
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
DescriptionWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Sapling SCM installations are affected?
Sapling SCM versions prior to v0.2.20260929-102736 are affected. Installations at or above that version are not identified as affected by the provided information.
2
What must an attacker do to trigger exploitation?
An attacker needs to provide a maliciously constructed repository containing Git subtree URLs with embedded control characters, and a target must clone that repository.
3
Can the issue be triggered during routine repository inspection?
Yes. After cloning the malicious repository, code execution can be triggered by otherwise read-only actions including sl log, blame, and annotate.