← back
CVE-2017-9462

CVE-2017-9462

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 22%
from disclosure to weapon0 days
Published on NVDJun 6
metasploitApr 18
exploitation probability
22%top 3% of all CVEs
observed exploitation
nono source reports it
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
Affected products
n/a · n/a