GCVE-VVD-MAGEIA-2017-182
Advisory Published
Vulnetix · Advisory published June 26, 2017
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

Affected Products

VendorProductVersionsPlatforms
Mageiamercurial0 (affected), 3.1.1-5.3.mga5 (unaffected)

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.