Path Traversal Vulnerability in Dancer2 by Perl
CVE-2026-93712

Currently unrated

Key Information:

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-93712?

The Dancer2 framework, specifically versions from 2.1.0 before 2.2.0, is susceptible to a path traversal vulnerability that allows attackers to access files outside the designated public directory. Through manipulation of the request path, unauthorized users may gain access to sensitive files such as the application's configuration files. This issue arises when the framework's File route handler improperly handles relative path segments, enabling access to resources beyond the intended scope. The vulnerability is inactive by default but poses a serious risk if the File handler is included in route handlers with static_handler set to 0.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.