Lucene search

K
osvGoogleOSV:GHSA-GHJX-3JG5-H6R2
HistoryJul 13, 2018 - 3:17 p.m.

High severity vulnerability that affects mercurial

2018-07-1315:17:10
Google
osv.dev
19

0.03 Low

EPSS

Percentile

91.0%

In Mercurial before 4.1.3, “hg serve --stdio” allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.