Executive brief
Config::IniFiles is a Perl module used to read and write configuration files. A security flaw in how it handles filenames allows an attacker to execute arbitrary system commands or overwrite files if the application passes untrusted input to the file loading function. This could lead to a full system compromise or data loss depending on the permissions of the application using the library.
Technical details
The Config::IniFiles::_make_filehandle function utilized Perl's 2-argument open() function to process the '-file' argument. In Perl, 2-argument open() interprets special characters such as pipes ('|') and redirects ('>') as shell commands or file redirections rather than literal paths. An attacker who can control the filename string passed to the library can execute arbitrary OS commands or truncate files with the privileges of the running process. The vulnerability was addressed in version 3.001000 by migrating to the secure 3-argument open() syntax, which treats the filename as a literal string.
Affected products
- Perl CPAN Config::IniFiles < 3.001000
Timeline
- 2026-06-08: patched: Fix committed to repository
- 2026-06-14: disclosed: CVE published to NVD