Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-56004

obs-service-tar_scm: command injection via mercurial handler
Back to all
CVE

CVE-2026-56004

obs-service-tar_scm: command injection via mercurial handler

A shellcode injection in the mercurial handler of the obs tarscm source service before version 0.12.4 could be used by attackers able to provide a service file to execute code as the source service or the local user checking out the malicious services

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
10
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56004.json, https://nvd.nist.gov/vuln/detail/CVE-2026-56004, https://github.com/openSUSE/obs-service-tarscm/pull/552/changes/bcf29d318c671c45fe87dd9f995a4a0c78ecedd7, https://github.com/openSUSE/obs-service-tarscm

Severity

10

CVSS Score
0
10

Basic Information

Base CVSS
10
EPSS Probability
0.00375%
EPSS Percentile
0.30886%
Introduced Version
0
Fix Available
991e3a1f2e87c0b611deefb8d95f38a2a25c42a3

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading