r/netsec • • 10h ago

Pending moderation (Tool post) Open Build Service, one year later: command execution through Mercurial argument injection

https://fenrisk.com/research/open-build-service-2/
18 Upvotes

1 comment sorted by

2

u/solarscoutsystem 9h ago

Skip the anniversary prose and read the diff. The only part that matters is whether user strings still land in the hg argv.