CVE-2026-42563 | jelmer dulwich up to 1.2.4 Merge Driver Command os command injection (GHSA-9277-mp7x-85jf)
A vulnerability was found in jelmer dulwich up to 1.2.4. It has been classified as critical. The affected element is an unknown function of the component Merge Driver Command Handler. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-42563. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.