Lucene search

K
osvGoogleOSV:PYSEC-2017-91
HistoryJun 06, 2017 - 9:29 p.m.

PYSEC-2017-91

2017-06-0621:29:00
Google
osv.dev
16

0.03 Low

EPSS

Percentile

91.0%

In Mercurial before 4.1.3, “hg serve --stdio” allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.