A critical vulnerability (CVE-2026-56004) has been disclosed in the Mercurial version control handler of the tar_scm source service component in openSUSE Build Service. This flaw, rated CVSS 10.0, enables attackers to execute arbitrary shellcode by crafting a malicious _service file. The vulnerability affects systems utilizing versions of tar_scm before 0.12.4, particularly when processing Mercurial repositories through the open build service (OBS) framework. Successful exploitation allows code execution under the context of the source service process or the local user performing repository checkouts. The vulnerability impacts openSUSE and SLES distributions that rely on the affected OBS components. Immediate mitigation requires upgrading to tar_scm version 0.12.4 or later. Systems exposed to untrusted _service file sources are at highest risk. No workarounds exist aside from applying the official patch. Organizations using automated CI/CD pipelines with Mercurial repositories should prioritize remediation to prevent potential remote code execution attacks.