Junglewise Threat Intelligence

CVE-2017-9462: PYSEC-2017-91 - In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbi

CVE-2017-9462 · Severity: low · CVSS 3.1 · Published 2017-06-06

Technologies: mercurial (PyPI). Vendors: PyPI.

Executive brief

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

Affected products

  • PyPI mercurial

Related threats