Junglewise Threat Intelligence

CVE-2026-48962: Perl IO::Compress eval injection in File::GlobMapper

CVE-2026-48962 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Perl CPAN IO-Compress. Vendors: Perl CPAN.

Executive brief

A vulnerability in a common Perl library used for file compression could allow an attacker to execute malicious code. By providing a specially crafted file naming pattern (glob), an attacker can break out of the intended command and run arbitrary instructions with the same permissions as the application. This could lead to a full system compromise or unauthorized data access depending on the application's privileges.

Technical details

An eval injection vulnerability exists in the File::GlobMapper component of the IO::Compress Perl library. The _parseOutputGlob() function wraps user-supplied output glob strings in double quotes and stores them; subsequently, the _getFiles() function executes this stored expression using 'eval STRING'. An attacker can provide a glob string containing a literal double quote to terminate the intended string wrapper and inject arbitrary Perl code. This code executes with the privileges of the process calling the library. The issue was resolved in version 2.220 by removing the use of eval in favor of a manual transformation logic.

Affected products

  • Perl CPAN IO::Compress before 2.220

Timeline

  • 2026-05-16: patched: Fix committed in version 2.220
  • 2026-05-27: disclosed: CVE-2026-48962 published

References