CVE-2026-15392
HIGHDBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
Title source: cnaDescription
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories. Callers of file-based drivers can read or write files outside of the data directory.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mh3j-xwf4-jrqw
Release Notes release-notes
https://metacpan.org/release/HMBRAND/DBI-1.651/changes
Scores
CVSS v3
7.7
EPSS
0.0016
EPSS Percentile
5.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
CWE-59
Status
published
Products (1)
HMBRAND/DBD::File
< 1.651
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026