CVE-2026-56004: obs-service-tar_scm: command injection via mercurial handler
A shellcode injection in the mercurial handler of the obs tarscm source service before version 0.12.4 could be used by attackers able to provide a service file to execute code as the source service or the local user checking out the malicious services
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
obs-service-tar_scm (obs tar_scm source service)to a version that resolves this vulnerability.Fixed in 0.12.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56004?
CVE-2026-56004 has a high severity rating of 8.8.
How do I fix CVE-2026-56004?
To fix CVE-2026-56004, upgrade Open Build Service obs-service-tar_scm to version 0.12.4 or later.
What type of vulnerability is CVE-2026-56004?
CVE-2026-56004 is categorized as an OS Command Injection and Code Injection vulnerability.
Who is affected by CVE-2026-56004?
Users of Open Build Service obs-service-tar_scm versions prior to 0.12.4 are affected by CVE-2026-56004.
How can an attacker exploit CVE-2026-56004?
An attacker can exploit CVE-2026-56004 by providing a malicious _service file that allows command injection in the mercurial handler.