THREAT OPS › Threat News › CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename
CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename
<p>Posted by Robert Rothenberg on Aug 13</p>========================================================================<br /> CVE-2026-13048 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-13048<br /> Distribution: Data-MuForm<br /> Versions: through 0.05<br />
Indicators of compromise
- CVE-2026-13048cve
- https://metacpan.org/dist/Data-MuFormurl
Original source: https://seclists.org/oss-sec/2026/q3/484