The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.
"https://github.com/pypa/advisory-database/blob/main/vulns/mercurial/PYSEC-2015-14.yaml"