CVE-2025-30672
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
01/04/2025
Last modified:
01/04/2025
Description
Mite for Perl before 0.013000 generates code with the current working directory (&#39;.&#39;) added to the @INC path similar to CVE-2016-1238.<br />
<br />
If an attacker can place a malicious file in current working directory, it may be <br />
loaded instead of the intended file, potentially leading to arbitrary <br />
code execution.<br />
<br />
This affects the Mite distribution itself, and other distributions that contain code generated by Mite.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM