PT-2026-90707 · Dbd::Dbm+2 · Dbd::Dbm+3
CVE-2026-78030
·
Published
2026-09-11
·
Updated
2026-09-29
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DBI versions prior to 1.653
Description
An issue in DBD::DBM allows the loading of arbitrary modules because the
dbm type and dbm mldbm connect attributes are passed to the require function without validation. Since require treats path-shaped strings as literal filenames and bypasses the @INC array, an attacker can specify a file path to load and execute arbitrary file-scope code. The MLDBM::Serializer:: prefix prepended to dbm mldbm does not act as a boundary, as values containing / can traverse out of the serializer directory. This can be exploited if an untrusted party can influence these attributes via a DSN fragment or a storage backend selection parameter. Additionally, DBD::Gofer forwards these attributes to the server side, and DBI::ProxyServer only verifies that a DSN starts with a driver prefix, potentially propagating the issue.Recommendations
Update DBI to version 1.653 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dbd::Dbm
Dbd::Gofer
Dbi
Dbi::Proxyserver