Executive brief
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
Affected products
- PyPI mercurial
Junglewise Threat Intelligence
CVE-2016-3068 · Severity: low · CVSS 3 · Published 2016-04-13
Technologies: mercurial (PyPI). Vendors: PyPI.
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.