CVE-2026-56004
A shellcode injection in the mercurial handler of the obs tarscm source service before version 0.12.4 could be used by attackers able to provide a service file to execute code as the source service or the local user checking out the malicious services
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56004.json, https://nvd.nist.gov/vuln/detail/CVE-2026-56004, https://github.com/openSUSE/obs-service-tarscm/pull/552/changes/bcf29d318c671c45fe87dd9f995a4a0c78ecedd7, https://github.com/openSUSE/obs-service-tarscm