YAML Vulnerability in Perl Allows Arbitrary Code Execution in Affected Versions
CVE-2019-25777

Currently unrated

Key Information:

Vendor

Perl

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2019-25777?

The vulnerability in YAML versions prior to 1.27_001 for Perl allows a crafted perl/glob document to replace any package variable, potentially leading to arbitrary code execution. This risk arises when the document specifies package names and symbols without restrictions, enabling the attacker to manipulate the loaded environment. If an attacker combines documents to invoke code loading, this can result in the execution of unintended Perl code, making it crucial for users to upgrade to the latest patched versions to mitigate potential threats.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.