LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-56004

Published
CVSS10
Severitycritical
WeaknessCWE-78
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services

References

← Back to the CVE Tracker

Our coverage of CVE-2026-56004

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-56004.