CVE-2016-3105: Debian Linux

High severity, CVSS 8.8. EPSS: 2.8% chance of exploitation in the next 30 days.

The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Mercurial Mercurial: up to and including 3.7.3

Published 2016-05-09. Last modified 2026-06-17.