
🚨Critical - openSUSE obs-service-tar_scm Command Injection via Mercurial Handler (CVE-2026-56004) A shellcode/OS command injection flaw (CWE-78) in the mercurial handler of the Open Build Service tar_scm source service lets an attacker who can supply a malicious _service file inject shell commands. The code executes as the OBS source service or as the local user checking out the malicious services. Since _service files drive source checkouts in OBS, a crafted package/project turns a normal build-time SCM fetch into arbitrary code execution. The flaw is remotely exploitable with no privileges and no user interaction, and CISA assessed it as automatable - a maximum-severity CVSS 10.0. 👉Upgrade obs-service-tar_scm to 0.12.4.
Post summary
The advisory reports a critical command‑injection vulnerability in openSUSE’s obs-service-tar_scm (CVE‑2026‑56004) and directs users to upgrade to version 0.12.4.



