CVE-2025-2361

A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument cmd leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

  • logo

    System detected CVE-2025-2361 with a risk of 2.29

  • logo

    System created a ticket for CVE-2025-2361

    Everything after this entry will be synced with the external system. The ticket can be found at https://github.com/l3montree-dev/devguard-action/issues/89

  • logo

    System detected CVE-2025-2361 on another ref: main

  • logo

    System created a ticket for CVE-2025-2361

    Everything after this entry will be synced with the external system. The ticket can be found at undefined

Add a comment

Mark as False Positive
Comment will be synced with https://github.com/l3montree-dev/devguard-action/issues/155
Last calculated at:

Affected component

Logo von deb debian/mercurial

Installed version:
6.3.2-1
Fixed in:
no patch available
Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version 667098114b5ef45c7830e7aa599604fa65eb818f