THREATOPS
THREAT OPSThreat News › CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename

CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename

medoss_secPublished 2026-08-13

<p>Posted by Robert Rothenberg on Aug 13</p>========================================================================<br /> CVE-2026-13048                                       CPAN Security Group<br /> ========================================================================<br /> <br />         CVE ID:  CVE-2026-13048<br />   Distribution:  Data-MuForm<br />       Versions:  through 0.05<br />

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/484