ELA-1463-1 mercurial security update

cross-site scripting

2025-06-17
Packagemercurial
Version4.0-1+deb9u3 (stretch), 4.8.2-1+deb10u2 (buster)
Related CVEs CVE-2025-2361


A cross-site scripting vulnerability was discovered in hgweb, the integrated stand-alone web interface of the Mercurial version control system.

This update also stabilizes the test suites.



For Debian 10 buster, these problems have been fixed in version 4.8.2-1+deb10u2.

For Debian 9 stretch, these problems have been fixed in version 4.0-1+deb9u3.

We recommend that you upgrade your mercurial packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.