CVE-2025-30672

MEDIUM

Mite for Perl <0.013000 - Code Injection

Title source: llm
STIX 2.1

Description

Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution. This affects the Mite distribution itself, and other distributions that contain code generated by Mite.

Scores

CVSS v3 6.5
EPSS 0.0054
EPSS Percentile 67.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
TOBYINK/Mite < 0.013000
Published Apr 01, 2025
Tracked Since Feb 18, 2026