Junglewise Threat Intelligence

CVE-2026-56004: openSUSE obs-service-tar_scm command injection in Mercurial handler

CVE-2026-56004 · Severity: high · CVSS 8.8 · Published 2026-07-02

Vendors: Opensuse.

Executive brief

A security vulnerability exists in the Open Build Service (OBS) tar_scm tool, which is used to manage source code during software building. An attacker can provide a specially crafted configuration file that triggers the execution of malicious commands on the system. This could allow an attacker to take control of the build service or the local computer of a user checking out the affected project.

Technical details

A command injection vulnerability (CWE-78) exists in the Mercurial (hg) handler of the obs-service-tar_scm source service before version 0.12.4. The issue stems from improper sanitization of options such as 'revision' and 'url' within the Mercurial integration. An attacker can exploit this by providing a malicious `_service` file to a project. When the service is executed—either by the automated Open Build Service or by a local user checking out the service—the injected shell commands are executed with the privileges of the service or the local user. The vulnerability was addressed by improving option sanitization in the affected Python components.

Affected products

  • openSUSE obs-service-tar_scm before 0.12.4

Timeline

  • 2026-07-01: patched: Fix merged in GitHub pull request 552
  • 2026-07-02: advisory: CVE-2026-56004 published by SUSE

References