{"id":"CVE-2017-1000116","aliases":["GHSA-3qmg-c9vc-r47j","PYSEC-2017-89"],"url":"https://o3.security/vulnerability/CVE-2017-1000116","summary":"Mercurial is vulnerable to shell injection attack","details":"Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.","published":"2017-10-05T01:29:04.617Z","modified":"2026-04-16T06:19:36.186672028Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"mercurial","fixedVersion":"4.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.2F_4.3.1_.282017-08-10.29"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3963"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/100290"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2489"},{"type":"FIX","url":"https://security.gentoo.org/glsa/201709-18"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000116"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mercurial/PYSEC-2017-89.yaml"},{"type":"WEB","url":"https://web.archive.org/web/20200227155758/http://www.securityfocus.com/bid/100290"},{"type":"WEB","url":"https://wiki.mercurial-scm.org/WhatsNew/Archive"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-16T06:19:36.186672028Z"}}