CVE-2026-15392
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
14/07/2026
Last modified:
15/07/2026
Description
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location.<br />
<br />
The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories.<br />
<br />
Callers of file-based drivers can read or write files outside of the data directory.
Impact
Base Score 3.x
7.70
Severity 3.x
HIGH



