CVE-2026-104026: Improper Neutralization of Escape, Meta, or Control Sequences (CWE-150) in Meta Platforms, Inc Sapling SCM
In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.
AI Analysis
Technical Summary
In Sapling SCM versions before 0.2.20260929-102736, improper neutralization of escape, meta, or control sequences (CWE-150) permits embedding of control characters in Git subtree URLs. This flaw can be exploited by cloning a maliciously crafted repository, triggering code execution in otherwise read-only commands like sl log, blame, or annotate.
Potential Impact
Successful exploitation can result in arbitrary code execution during read-only operations on a cloned repository, potentially compromising the system or user environment where Sapling SCM is used.
Mitigation Recommendations
A fix is available in Sapling SCM version 0.2.20260929-102736 and later. Users should upgrade to this version or newer to remediate the vulnerability. No additional mitigation steps are indicated.
CVE-2026-104026: Improper Neutralization of Escape, Meta, or Control Sequences (CWE-150) in Meta Platforms, Inc Sapling SCM
Description
In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.
CVSS v3.1
Score 7.8high
Affected software
Meta Platforms, Inc
Sapling SCM
pkg:github/meta/saplingRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Sapling SCM versions before 0.2.20260929-102736, improper neutralization of escape, meta, or control sequences (CWE-150) permits embedding of control characters in Git subtree URLs. This flaw can be exploited by cloning a maliciously crafted repository, triggering code execution in otherwise read-only commands like sl log, blame, or annotate.
Potential Impact
Successful exploitation can result in arbitrary code execution during read-only operations on a cloned repository, potentially compromising the system or user environment where Sapling SCM is used.
Mitigation Recommendations
A fix is available in Sapling SCM version 0.2.20260929-102736 and later. Users should upgrade to this version or newer to remediate the vulnerability. No additional mitigation steps are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Meta
- Date Reserved
- 2026-10-01T17:11:09.874Z
- State
- PUBLISHED
Threat ID: 6abfc057a43b0b3b89c72422
Added to database: 10/02/2026, 14:31:51 UTC
Last enriched: 10/02/2026, 14:46:08 UTC
Last updated: 10/02/2026, 14:55:19 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.