CVE-2026-104026: Meta Platforms, Inc Sapling Scm

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.

Affected products

  • Meta Platforms, Inc Sapling Scm: from v0.0.0, before v0.2.20260929-102736 (fixed in v0.2.20260929-102736)

Published 2026-10-02. Last modified 2026-10-02.