AI and data stack advisories

Severe, 6 weeks2973Projects319

2973 severe, 6 weeks · 319 projects

MetaCVE-2026-104026

Meta Sapling SCM: code execution

Meta

CVE-2026-104026 · Published Oct 2, 2026

High7.8
Fix: upgrade to v0.2.20260929-102736 or later
Meta advisory

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.

Affected versions

PackageAffectedFixed in
Sapling SCM
Product
>= v0.0.0, < v0.2.20260929-102736v0.2.20260929-102736
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-150

More Meta advisories

All Meta
Advisory
Prior to v66.0.0.733.524 of Meta Horizon OS
High8.8Sep 30
Prior to v74.0.0.878.1682 of Meta Horizon OS
Critical9.1Sep 30
Meta proxygen: use after free
High7.3Sep 28
Meta proxygen: use after free
Medium5.3Sep 28
Meta proxygen: use after free
High7.5Sep 28
Meta moxygen: use after free
High7.5Sep 28