


Perceptive Security
SOC/SIEM Consultancy

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service fil…
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 17:05:10
Source:
nvd.nist.gov
Supply Chain & Dependencies, Zero-Day Vulnerabilities, Security Tools
CVE-2026-56004 describes a shellcode injection vulnerability in the Mercurial handler of the obs-service-tar_scm source service used in openSUSE Open Build Service (OBS). The flaw exists in versions before 0.12.4 and can be exploited by attackers who are able to supply a malicious _service file. Successful exploitation allows arbitrary code execution either as the source service process or as the local user who checks out the malicious service. The vulnerability is rooted in insufficient sanitization of inputs passed to the Mercurial handler. A patch has been proposed via a GitHub pull request to the openSUSE obs-service-tar_scm repository. The issue represents a supply chain risk as build environments processing attacker-controlled _service files could be compromised. Users are advised to upgrade to version 0.12.4 or later to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
obs-service-tar_scm
openSUSE Open Build Service
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-56004
https://github.com/openSUSE/obs-service-tar_scm/pull/552/changes/bcf29d318c671c45fe87dd9f995a4a0c78ecedd7
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
